Detection Content Engineer: KQL & Sentinel Automation

BlueVoyant

Greater London

Hybrid

GBP 70,000 - 100,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

BlueVoyant seeks a Security Content Engineer to join its Threat Fusion Cell, building automated security analysis solutions. This fully remote role in the UK focuses on developing, tuning and maintaining detection content for global clients.

You will lead threat-informed research, design scalable automation for onboarding and enrichment, and advise clients on detection logic with strong MS security stack skills and deep KQL expertise.

Qualifications

  • 5-8 years of direct experience in Detection Engineering, SOC, or a similar role with a heavy focus on content creation.
  • Hands-on expertise with the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps.
  • High proficiency in Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting.
  • Strong, demonstrated experience automating security workflows using SOAR platforms, APIs, or scripting languages (Python, PowerShell).
  • Proven ability to operate with a high degree of autonomy, managing competing priorities and complex projects with minimal supervision.
  • In-depth knowledge of attacker TTPs, the MITRE ATT&CK framework, and modern blue team operations.
  • Excellent analytical and problem-solving skills, with experience in deep log analysis and digital forensics.
  • Strong collaboration and communication skills, with the ability to clearly explain complex technical concepts.

Responsibilities

  • Own and Enhance Detection Content: Autonomously develop, test, and maintain high-fidelity detection logic in KQL for the Microsoft Sentinel environment.
  • Conduct Advanced Tuning & Optimization: Perform independent and complex global tuning to improve SOC efficiency and outcomes.
  • Lead Threat-Informed Research: Independently research emerging threats, attack vectors, and high-risk vulnerabilities to design and develop proactive detection strategies.
  • Develop Scalable Automation: Design and build automation content for key security workflows, including product onboarding and incident enrichment.
  • Serve as a Technical Resource: Act as a knowledgeable point of contact for clients on complex tuning requests and provide clear guidance on detection logic.
  • Improve Team Frameworks: Contribute to the evolution of security policies and automation frameworks by providing expert feedback.

Skills

Detection Engineering
SOC operations
KQL
Automation scripting
Python
PowerShell
MITRE ATTACK
Microsoft Sentinel
Logic Apps

Tools

Git
SOAR platforms

Job description

BlueVoyant seeks a Security Content Engineer to join its Threat Fusion Cell, building automated security analysis solutions. This fully remote role in the UK focuses on developing, tuning and maintaining detection content for global clients.

You will lead threat-informed research, design scalable automation for onboarding and enrichment, and advise clients on detection logic with strong MS security stack skills and deep KQL expertise.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote UK: Threat Detection Content Engineer
Remote UK: Threat Detection Content Engineer

BlueVoyant • United Kingdom

Remote
GBP 75,000 - 120,000
Security Content Engineer
Security Content Engineer

BlueVoyant • Greater London

Hybrid
GBP 70,000 - 100,000
Senior Detection Engineer for SOC Automation
Senior Detection Engineer for SOC Automation

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Security Detection Engineer - Cloud SIEM & Threat Hunting
Security Detection Engineer - Cloud SIEM & Threat Hunting

McCabe & Barton • Greater London

On-site
GBP 70,000 - 110,000
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Security Detection Engineer
Security Detection Engineer

McCabe & Barton • Greater London

On-site
GBP 70,000 - 110,000
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Southampton

Hybrid
GBP 72,000 - 88,000
Performance-based bonuses
Collaborative engineering environment
Industry-leading benefits
Senior Security Detection & Automation Architect
Senior Security Detection & Automation Architect

InfoSec People Ltd • Basingstoke

Hybrid
GBP 75,000 - 110,000
Hybrid working model
Competitive salary
Comprehensive employee benefits
+4
Senior Security Engineering Consultant
Senior Security Engineering Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 75,000 - 110,000
Hybrid working model
Competitive salary
Comprehensive employee benefits
+4
Cyber Security Engineer - Threat Detection
Cyber Security Engineer - Threat Detection

Intercontinental Exchange Holdings, Inc. • City Of London

On-site
GBP 70,000 - 110,000