Quick Overview
Job Description
Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands-on technical position within the Security Operations domain, focused on helping customers improve and automate their SOC functions, tooling, and detection capabilities.
Key Responsibilities:
Design and deliver detection rulesets across SIEM and XDR platforms<br />Develop and tune detection logic using KQL or equivalent query languages<br />Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques<br />Map customer log sources to detection use cases to assess coverage and identify gaps<br />Design and implement SOAR automations, integrations and response workflows<br />Develop and document customer incident response playbooks aligned to detection outputs<br />Translate threat intelligence and operational learnings into improved detections and automations<br />Deliver detection as code pipelines, including structured use case development and versioning approaches<br />Produce clear technical and customer-facing deliverables, including detection strategies, use case catalogues and coverage assessments<br />Work directly with customers as a trusted technical consultant<br />Lead workshops covering detection engineering, use case design and SOC maturity<br />Guide customers on improving detection coverage and aligning to MITRE ATT&CK<br />Clearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholders<br />Work closely with platform onboarding and engineering teams to ensure smooth integration of delivered detections and automations<br />Support SOC teams by ensuring delivered outputs are practical, usable and aligned to operational workflows<br />Contribute to the continuous evolution of detection use cases, playbooks and automation patterns<br />Support development of reusable detection content and delivery standards<br />Contribute to lab work, testing and validation of detection approaches<br />Identify gaps in telemetry, logging and enrichment, and provide recommendations to strengthen detection outcomes Job
Requirements:
Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred<br />Experience writing detection logic using KQL or similar query languages<br />Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar<br />Scripting and automation capability using Python, PowerShell or similar, including working with APIs<br />Experience designing detection use cases aligned to MITRE ATT&CK<br />Strong understanding of detection coverage and how log sources map to the attack lifecycle<br />Experience with XDR or EDR platforms such as Microsoft Defender, CrowdStrike or Cortex<br />Understanding of cloud environments, particularly Azure, and associated security telemetry<br />Experience working in customer-facing or consultancy roles<br />Strong communication skills, with the ability to explain technical concepts clearly Technical Competencies: SIEM and XDR platforms, including Microsoft Sentinel, Microsoft Defender, Palo Alto XSIAM or XDR, CrowdStrike and SentinelOne<br />SOAR development, including automation and playbook design using platforms such as Palo Alto XSOAR or similar<br />Scripting and integration using Python, PowerShell or similar, including API-driven automation<br />Detection engineering aligned to MITRE ATT&CK, including use case design, ruleset development and coverage assessment<br />Log source mapping and normalisation to support detection use cases<br />Network Detection and Response technologies such as Vectra AI, Corelight or similar<br />Cloud security and telemetry, particularly within Azure environments<br />Threat intelligence integration and enrichment to support detection and response<br />Development of customer playbooks and response workflows aligned to SOC operations<br />General awareness of emerging technologies, including AI-driven security tooling and their application within detection and response Job Specifics: Location: This is a hybrid role, primarily remote but with a requirement of ad-hoc travel to customer sites and attend the Basingstoke office as required to support delivery, workshops and engagements.<br />Hours: Full-time, Monday - Friday, 9:00am - 5:30pm. There is no on-call requirement for this position.
Benefits:
Salary up to £80,000 Performance-based bonuses<br />Industry-leading benefits<br />A collaborative engineering environment<br />Exposure to real-world threats and modern detection approaches<br />Opportunity to shape Security Operations capabilities<br />If you are a skilled Security Engineering Consultant looking to join a dynamic and impactful team, we encourage you to apply now and be a part of building a secure and connected future with our client
Similar jobs
- AM
Security Architect
NewAnson Mccade
London🇬🇧£110k/yrHybrid2 minutes agoZero TrustTechnology - JR
Fire & Security Engineer
JLB Recruitment Ltd
United Kingdom🇬🇧On-site4 months agoTechnology - PF
Fire And Security Engineer
NewProtec Fire & Security Group Ltd
Great Bowden, Market Harborough🇬🇧On-siteYesterdayTechnology - IR
Senior Security Installation Engineer
Infinity Resource Solutions
Chesham Bois, Amersham🇬🇧£45 - £50/hrHybrid4 months ago - IR
Security Engineer
Infinity Resource Solutions
Well End, Borehamwood🇬🇧£40k/yrHybrid4 months agoTechnology - IR
Senior Security Service Engineer
Infinity Resource Solutions
Chesham Bois, Amersham🇬🇧£45 - £50/hrHybrid4 months ago