Detection Engineer Microsoft Sentinel & Defender XDR - Netbuilder

OpenTalent

Greater London

Hybrid

GBP 63,000 - 77,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

NETbuilder in London is seeking an experienced Detection Engineer for our Security and Observability practice. The role is hybrid and focused on developing and enhancing detection across Microsoft security platforms for global client environments.

You will write and optimise KQL queries, investigate data quality gaps, and translate threat intel into practical use cases while collaborating with SOC, Threat Hunting and Incident Response teams to improve outcomes.

Qualifications

  • 4+ years in detection/security engineering roles.
  • Hands-on with Microsoft Sentinel and Defender XDR.
  • Proficient in writing and tuning KQL queries.
  • Understanding of log pipelines and telemetry quality.
  • Experience with MITRE ATT&CK framework.

Responsibilities

  • Develop, test and maintain detection rules across Microsoft Sentinel and Defender XDR.
  • Write and optimise KQL queries to identify suspicious activity and security events.
  • Analyse telemetry and investigate data quality gaps.
  • Translate threat intelligence into practical detection use cases.
  • Collaborate with SOC, Threat Hunting and IR teams to improve outcomes.
  • Use PowerShell or Python to automate tasks and detection workflows.
  • Contribute to detection engineering standards and best practices.

Skills

Detection engineering
KQL queries
PowerShell or Python
Threat detection methodologies
Team collaboration
Client-facing experience

Tools

Microsoft Sentinel
Microsoft Defender XDR

Job description

London (Hybrid) 6-month FTC

We’re hiring for an experienced Detection Engineer to join our Security and Observability practice, working across a range of global client environments.

You’ll be responsible for developing and enhancing detection capabilities across modern Microsoft security platforms, using Microsoft Sentinel, Defender XDR and KQL to develop, test and optimise effective detection logic.

The role combines hands-on engineering with problem-solving and collaboration. You’ll work with security teams to identify gaps, investigate detection challenges, improve existing use cases and develop new capabilities in response to changing threats and operational requirements.

If you enjoy getting into the detail of security data, writing detection logic and continuously finding ways to make detection capabilities more effective, we’d like to hear from you.

What you’ll be doing:
  • Develop, test and maintain detection rules across Microsoft Sentinel and Defender XDR.
  • Write and optimise KQL queries to identify suspicious activity and security events.
  • Analyse telemetry and investigate gaps in data quality, coverage and detection capability.
  • Translate threat intelligence and security requirements into practical detection use cases.
  • Work with SOC, Threat Hunting and Incident Response teams to improve detection outcomes.
  • Use PowerShell or Python to automate repetitive tasks and enhance detection workflows.
  • Contribute to the ongoing development of detection engineering standards and best practices.
What you’ll bring:
  • 4+ years' experience in Detection Engineering, Security Engineering, SOC Engineering, Threat Detection or a related cybersecurity role
  • Hands-on experience creating, developing and tuning detections in Microsoft Sentinel and Microsoft Defender XDR
  • Strong hands-on experience writing and optimising KQL queries
  • Strong understanding of log pipelines, schema mapping and telemetry quality, including ASIM
  • Experience tuning detections, reducing false positives and improving detection coverage
  • Scripting experience with PowerShell or Python
  • Good understanding of threat detection methodologies, including MITRE ATT&CK
  • Ability to work collaboratively across cyber security, technology and operational teams
  • Experience working in a client-facing, consulting or managed services environment would be advantageous
Why join NETbuilder?

Ourhistory is deeply rooted in the digital landscape, meaning we bring decades of experience and unrivalled expertise to every project we work on. You will join a world-class team of experienced consultants and be given the full support, resources, and backing to build something genuinely new within the NETbuilder group.

Pay: From £70,000.00 per year
Work Location: Hybrid remote in London
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer: Sentinel & Defender XDR (Hybrid,6m FTC)
Detection Engineer: Sentinel & Defender XDR (Hybrid,6m FTC)

OpenTalent • Greater London

Hybrid
GBP 63,000 - 77,000
Detection Engineer
Detection Engineer

Cybanetix • Greater London

On-site
GBP 65,000 - 95,000
Hands-on experience with modern SIEM and XDR platforms
Exposure to real-world attacker behaviors
Opportunity for career advancement
SOC Engineer Detection
SOC Engineer Detection

Sopra Steria Ltd • Farnborough

Hybrid
GBP 55,000 - 60,000
Health Shields
Life assurance
Pension
+2
Security Engineer - Systems Integrator
Security Engineer - Systems Integrator

Hamilton Barnes Associates Limited • Greater London, Cardiff

Hybrid
GBP 41,000 - 50,000
Primarily remote work
Occasional office attendance (London /
Client-facing responsibilities
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Detection Engineer: Master Microsoft Sentinel & Defender XDR
Detection Engineer: Master Microsoft Sentinel & Defender XDR

Aviva • Bristol

On-site
GBP 39,000 - 65,000
Bonus: 10% of annual salary
Generous pension—Aviva contributes up,
Private medical benefit
+2
Principal Analyst Detection Engineering - Technology Vendor
Principal Analyst Detection Engineering - Technology Vendor

Hamilton Barnes Associates Limited • United Kingdom

Remote
GBP 60,000 - 70,000
Remote-first with travel
Cyber Security Engineer
Cyber Security Engineer

Additional Resources • Greater London

Hybrid
GBP 60,000 - 80,000
Senior Security Engineer Consultant
Senior Security Engineer Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits
Senior Detection Engineer - Microsoft Sentinel (KQL)
Senior Detection Engineer - Microsoft Sentinel (KQL)

Sopra Steria Ltd • Farnborough

Hybrid
GBP 55,000 - 60,000
Health Shields
Life assurance
Pension
+2