Senior Security Engineer - Microsoft Sentinel & Defender XDR
RemoteLondon Area, United KingdomseniorFull-time
- Posted
- today
- Source
- LinkedIn (remote, Europe)
- Field
- Engineering, Security
Skills
OnboardingLeadershipAnalyticsSecurityPythonAzureAWS
Description
Senior Security Engineer
London (Hybrid)
Salary dependent on experience
We are looking for a Senior Security Engineer to design, build, and mature security monitoring, logging, and detection across Microsoft security platforms. You will work with Microsoft Sentinel, Microsoft Defender XDR, KQL, and automation tooling to improve detection coverage, onboard data sources, and strengthen enterprise security monitoring.
This is a role for someone who works with real autonomy. You will identify the problems, define the solutions, and deliver the outcomes, working closely with security, engineering, and operations teams.
What You Will Do
- Lead the onboarding and integration of complex environments into the wider security architecture.
- Design target-state logging, monitoring, and detection architectures, and produce Low-Level Designs (LLDs) and technical documentation.
- Lead migrations from platforms such as Splunk and CrowdStrike to Microsoft Sentinel and Defender.
- Design centralized and multi-tenant logging solutions across Microsoft and AWS environments.
- Establish logging and security foundations where existing capability is immature or inconsistent.
- Build, test, and maintain detections in Microsoft Sentinel and Defender XDR, writing and optimizing KQL to surface suspicious activity.
- Define logging requirements, collection methods, and ingestion approaches, and build the pipelines that bring data sources into Sentinel.
- Analyze telemetry to find gaps in data quality, coverage, and detection capability.
- Tune detections to cut false positives and improve monitoring effectiveness.
- Turn threat intelligence into practical detection use cases.
- Work with SOC, Threat Hunting, and Incident Response teams to improve outcomes.
- Automate processes with PowerShell or Python.
- Provide technical leadership, mentoring, and architectural guidance to other engineers.
- Make key technical decisions and drive delivery across complex environments.
What You Will Bring
- Extensive experience designing and implementing enterprise-scale security monitoring and detection in a Security Engineering, Detection Engineering, or SOC Engineering role.
- Deep expertise in Microsoft Sentinel, Defender XDR, and advanced KQL, plus hands-on experience with Intune.
- Strong grasp of SIEM, logging architecture, detection engineering, and endpoint security.
- Experience designing logging architectures and producing technical designs and LLDs.
- A track record of leading security platform migrations and transformation programs.
- Strong understanding of Azure, AWS, and multi-environment security architectures.
- Working knowledge of MITRE ATT&CK and security monitoring best practice.
- Scripting experience in PowerShell and/or Python.
- The ability to set architectural direction, make technical decisions, and lead complex initiatives independently.
- Experience mentoring engineers and working with stakeholders at all levels.
Key Technologies
Microsoft Sentinel • Microsoft Defender XDR • Defender for Endpoint • Intune • Azure Log Analytics • KQL • PowerShell • Python • Cribl (desirable) • Splunk • CrowdStrike • AWS • MITRE ATT&CK
Why Join NETbuilder?
NETbuilder has been a specialist technology partner since 1999. You will join a team of experienced security consultants and have the support, resources, and backing to build a genuinely new capability.
JobMatch aggregates public listings. Always apply through the original posting.