Security Engineer - Microsoft Sentinel & Defender XDR (Various levels)
RemoteLondon Area, United KingdomseniorFull-time
- Posted
- 1 week ago
- Source
- LinkedIn (remote, Europe)
- Field
- Engineering, Security
Skills
RecruitingOnboardingLeadershipAnalyticsSecurityPythonAzureAWS
Description
London (Hybrid)
Salary (Dependent on experience)
Security Engineer (Mid-Senior & Senior)
We are seeking Security Engineers to help develop, enhance and mature security monitoring, logging and detection capabilities across Microsoft security platforms. Working with Microsoft Sentinel, Microsoft Defender XDR, KQL and automation technologies, you will play a key role in improving detection coverage, onboarding data sources and strengthening enterprise security monitoring
We are recruiting for both Mid-Senior Security Engineer and Senior Security Engineer positions. Both roles require a high degree of autonomy and ownership, with individuals expected to identify challenges, define solutions and deliver outcomes with minimal supervision while collaborating closely with security, engineering and operational teams.
What You'll Be Doing
Mid-Senior Security Engineer
- Develop, test and maintain detections within Microsoft Sentinel and Defender XDR.
- Write and optimise KQL queries to identify suspicious activity and security events.
- Design and implement logging pipelines and onboard data sources into Sentinel.
- Define logging requirements, collection methods and ingestion approaches.
- Analyse telemetry to identify gaps in data quality, coverage and detection capability.
- Tune detections, reduce false positives and improve monitoring effectiveness.
- Translate threat intelligence into practical detection use cases.
- Work with SOC, Threat Hunting and Incident Response teams to improve outcomes.
- Use PowerShell or Python to automate processes and improve efficiency.
- Independently manage and deliver assigned workstreams.
Senior Security Engineer
In addition to the above:
- Lead the onboarding and integration of complex environments into the wider security architecture.
- Design target-state logging, monitoring and detection architectures.
- Produce Low-Level Designs (LLDs) and technical documentation.
- Lead migrations from platforms such as Splunk and CrowdStrike to Microsoft Sentinel and Defender.
- Design centralised and multi-tenant logging solutions across Microsoft and AWS environments.
- Establish logging and security foundations where capabilities are immature or inconsistent.
- Drive improvements in detection maturity, monitoring coverage and security posture.
- Provide technical leadership, mentoring and architectural guidance.
- Operate with significant autonomy, making key technical decisions and driving delivery across complex environments.
What You'll Bring
Mid-Senior Security Engineer
- Experience in Security Engineering, Detection Engineering, SOC Engineering or a similar cyber security role.
- Hands-on experience with Microsoft Sentinel, Defender XDR and Intune.
- Strong understanding of SIEM, logging architecture, detection engineering and endpoint security.
- Experience with KQL and PowerShell and/or Python.
- Knowledge of MITRE ATT&CK and security monitoring best practices.
- Experience onboarding data sources, tuning detections and improving detection coverage.
- Ability to work independently, take ownership of deliverables and solve problems proactively.
Senior Security Engineer
In addition to the above:
- Extensive experience designing and implementing enterprise-scale security monitoring and detection capabilities.
- Deep expertise in Microsoft Sentinel, Defender XDR and advanced KQL.
- Experience designing logging architectures and producing technical designs/LLDs.
- Proven experience leading security platform migrations and transformation programmes.
- Strong understanding of Azure, AWS and multi-environment security architectures.
- Ability to independently define architectural direction, make technical decisions and lead complex initiatives.
- Experience mentoring engineers and engaging with stakeholders at all levels.
Key Technologies
Microsoft Sentinel • Microsoft Defender XDR • Defender for Endpoint • Intune • Azure Log Analytics • KQL • PowerShell • Python • Cribl (desirable) • Splunk • CrowdStrike • AWS • MITRE ATT&CK
Why join?
NETbuilder's history is deeply rooted in the digital landscape, meaning we bring decades of experience and unrivalled expertise to every project we work on. You will join a world-class team of experienced consultants and be given the full support, resources, and backing to build something genuinely new within the NETbuilder group.
JobMatch aggregates public listings. Always apply through the original posting.