> Markdown version of [/jobs/ext/3521046-security-engineering-consultant-detection-engineering-microsoft-sentinel](https://www.wearedevelopers.com/jobs/ext/3521046-security-engineering-consultant-detection-engineering-microsoft-sentinel). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineering Consultant (Detection Engineering / Microsoft Sentinel) - **Company:** Fazer Recruitment - **Location:** London, UK (Remote available) - **Experience:** Expert - **Salary:** £80,000.0 - £85,000.0 - **Contract:** Permanent contract - **Skills:** ARM Architecture, Microsoft Azure, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Kusto Query Language, Security Information and Event Management, Management of Software Versions, Microsoft Power Automate, Mitre Att&ck, Microsoft Sentinel, Cortex XSOAR Platform, SentinelOne Expertise - **Published:** October 2, 2026 - **Apply:** https://www.reed.co.uk/jobs/security-engineering-consultant-detection-engineering-microsoft-sentinel/57416772 ## About the Role * Strong SIEM engineering experience, ideally Microsoft Sentinel * Proven KQL detection writing * SOAR experience (Logic Apps, Cortex XSOAR or similar) * Python or PowerShell scripting, including API integration * XDR/EDR experience (Defender, CrowdStrike, Cortex or similar) * Azure security telemetry knowledge * Consultancy or customer-facing background, with excellent communication skills Nice to have: XSIAM, SentinelOne, NDR tools (Vectra, Corelight), threat intelligence enrichment. ## Description Our client, a well-established cybersecurity services provider, is growing its UK Professional Services team and needs a Senior Security Engineering Consultant to lead detection engineering and automation for its customers. This is a hands-on, customer-facing role. You'll design and deliver detection and response capabilities across SIEM, XDR and SOAR platforms, working alongside a dedicated SOC engineering team. You'll also own a "detection as code" approach, so detections and automations are built consistently and at scale. What you'll do * Build and tune detection rulesets in KQL (or equivalent) across SIEM and XDR platforms * Design use cases aligned to MITRE ATT&CK and assess coverage against customer log sources * Develop SOAR automations, integrations and incident response playbooks * Deliver detection as code pipelines with structured versioning * Lead customer workshops on detection strategy and SOC maturity * Produce clear deliverables such as detection strategies, use case catalogues and coverage assessments