Senior Security Engineer (Defender / Sentinel)
Remote - £60,000 - £80,000k
UK Applicants ONLY
You'll be the engineer who makes Defender and Sentinel actually work for enterprise customers: deploying them, tuning them, automating around them, and working with SOC Analysts to sharpen what gets detected. This is a hands-on build role at a specialist Microsoft security partner, with clear scope to progress and train as the team grows.
The essentials
- £60,000 to £80,000
- Hybrid, mostly remote, with one day per month in the London office
- Senior engineer, sitting in the Microsoft Cyber Engineering team
What you'll actually do
- Implement and support Microsoft security products for customers, primarily Defender and Sentinel, plus the adjacent security suite
- Carry out regular assessments of customer Microsoft tenants, covering configuration reviews, audits and architecture reviews
- Design, build and deploy automation across the SOC, from scripting and playbooks within the SIEM to broader workflows that remove manual effort and improve how the SOC operates day to day
- Work with SOC Analysts to improve detection capability and feed those improvements back into the automation you've built
- Research and introduce new technologies into the SOC
- Design and refine engineering standards and best practices, and document security processes
- Help triage and resolve incidents, draft customer-facing reports to a high standard, and support the development of more junior engineers
What you'll need
Essential:
- A solid background as a Security Engineer or SOC Engineer
- Hands-on experience with Microsoft Security technologies and KQL
- Experience with SIEM platforms, for example Sentinel, Splunk, Rapid7 or LogRhythm
- Ability to lead and design automation and scripting in SIEM tools
- Experience analysing cloud security risks, performing cloud security audits and recommending controls
- At least one relevant Microsoft certification (AZ-104, SC-200, AZ-500 or AZ-305) and fluent written and spoken English for client reports and calls
Nice to have:
- Prior experience working inside a SOC environment
- Exposure to the wider Microsoft Security portfolio, such as Entra, Purview, Intune or Copilot for Security
What's in it for you
You'll work across multiple enterprise environments rather than one, with structured training and career development as part of the role. The working pattern is largely remote with a single monthly day in London.