About this role
Salary: £70,000 - 70,000 per year
Requirements: Strong Security Engineer, security engineering, or detection engineering experienceHands-on SIEM and XDR tooling experience, ideally Microsoft Sentinel and Microsoft Defender for EndpointExperience with detection engineering, detection-as-code, KQL, security content, and alert logicExperience with security telemetry, logging pipelines, data quality, and improving telemetry coverageExperience in cloud security engineering and scalable security architecture designExperience with automation, SOAR, playbooks, enrichment workflows, and response improvementScripting or programming skills such as Python and PowerShellExperience with infrastructure-as-code, CI/CD pipelines, version control, and documentation standardsExperience integrating APIs, security tooling, and onboarding new data sourcesKnowledge of Windows and Linux operating systemsAbility to own engineering backlog, priorities, and delivery across detection and platform improvementsUK-based and able to travel to UK sites at short notice Responsibilities: Design, build, and maintain scalable security detection and response capabilities across SIEM, XDR, cloud, and endpoint platformsSet engineering direction, standards, and quality across detection, telemetry, and automationFocus on detection-as-code, telemetry optimisation, and automated response workflowsWork closely with SOC leadership and engineering teams to improve detection effectivenessIntegrate new data sources and enhance logging qualityBuild automation and support scalable cloud security outcomes Technologies: AzureCI/CDCloudSupportLinuxPowerShellPythonSecurityWindowsAPI More:
We are a leading tech company offering a permanent Security Engineer (SIEM / XDR) opportunity in our London office on a hybrid basis, with attendance typically 1-2 times a month. We offer a great package and strong career progression, and the role sits within a collaborative environment working closely with SOC leadership and engineering teams to improve detection, telemetry, automation, and cloud security outcomes. Desirable experience includes InfoSec, Microsoft, or Azure certifications.
last updated 39 week of 2026