About this role
Salary: £60,000 - 90,000 per year
Requirements: Strong commercial experience with Microsoft Sentinel / Azure SentinelStrong commercial experience with Microsoft Defender / Defender XDRStrong KQL / Kusto Query Language capabilityExperience in Security Engineering, SOC Engineering or Microsoft Security ConsultingSIEM engineering experience rather than solely alert monitoring or incident triageExperience in detection engineering and security monitoring optimisationExperience with automation, scripting, SOAR or Sentinel playbooksExperience with cloud security assessments, controls and risk analysisExperience designing and documenting security processesCustomer-facing technical delivery experienceRelevant Microsoft certifications are strongly preferred, particularly SC-200, AZ-500, AZ-104 or AZ-305, or equivalent/additional Microsoft Security certifications Responsibilities: Design, implement and support Microsoft Sentinel and Microsoft Defender / Defender XDR solutionsEngineer and optimise SIEM capabilities across enterprise environmentsDevelop and tune KQL queries, analytics and detection rulesDesign and implement SOC automation, playbooks and scriptingImprove security event detection and response capabilitiesConduct Microsoft tenant health checks, security audits and architecture reviewsAnalyse cloud security risks and recommend appropriate security controlsSupport complex incident triage and resolutionDesign and document security engineering standards and processesResearch and implement new Microsoft security capabilitiesProduce high-quality technical and customer-facing documentationWork directly with customers and technical stakeholdersSupport and mentor more junior members of the engineering team Technologies: AzureCloudSupportSecurityArchitectOffice 365PowerShellPython More:
We are a specialist Microsoft Security organisation working predominantly remotely, with occasional presence in London, and we are growing our Microsoft Cyber Engineering team. We offer the opportunity to work on complex customer engagements across the wider Microsoft Security ecosystem, alongside experienced security professionals. This is a highly specialised environment with continued investment in technical training and development, suited to an established Microsoft Security Engineer who wants to remain hands-on while taking greater ownership of solution design, engineering standards and security operations capabilities.
last updated 34 week of 2026