Head of Security Monitoring & Detection Engineering

Aj Bell

Manchester

On-site

GBP 90,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

AJ Bell is seeking a hands-on Cyber Defence Operations Lead to own the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate, based in Manchester.

You will translate real-world adversary behaviour into effective monitoring and response, drive complex investigations, develop playbooks and ensure coordinated action with the MSSP and internal teams to reduce risk.

Responsibilities

  • Own the technical direction, quality and delivery performance of Security Monitoring & Detection Engineering, translating priorities into a clear roadmap for monitoring, detection, investigation and response.
  • Lead the architecture, engineering and continued development of the SIEM solution, ensuring resilience, scalability and alignment with technology estate and threat profile.
  • Define onboarding of security telemetry across on-premises, Azure, AWS and third-party services, ensuring value for detection and investigation.
  • Own the detection engineering lifecycle from requirements to retirement, with version control and controlled release practices.
  • Lead analytics rules, hunting queries, workbooks and automated investigation and response workflows.
  • Ensure operational effectiveness of security solutions managed by CDO with measurable outcomes.
  • Drive threat-informed defence with Threat Intelligence and Exposure Management, translating adversaries into detections and defensive actions.
  • Maintain evidence-based service performance through KPIs and MI, driving corrective actions to measurable outcomes.
  • Lead technical escalation for complex security events, guiding investigations and containment.
  • Lead tabletop, purple-team and practical exercises to test detection coverage and readiness.
  • Operate the internal team and MSSP as one integrated monitoring and response capability, ensuring escalation consistency and performance.
  • Maintain alert demand, detection quality and MTTA/MTTR metrics to prioritise improvements.
  • Lead service reviews with vendors to maximise value of investments to CDO's objectives.
  • Identify and deliver automation opportunities across detection, enrichment, investigation and response.

Job description

AJ Bell is seeking a hands-on Cyber Defence Operations Lead to own the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate, based in Manchester.

You will translate real-world adversary behaviour into effective monitoring and response, drive complex investigations, develop playbooks and ensure coordinated action with the MSSP and internal teams to reduce risk.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Monitoring & Detection Lead — SIEM & Incident Response
Security Monitoring & Detection Lead — SIEM & Incident Response

SmartRecruiters, Inc. • Manchester, Greater London

Hybrid
GBP 120,000 - 150,000
27 days holiday
Pension matched contributions
Discretionary bonus
+6
Security Monitoring & Detection Engineering Lead
Security Monitoring & Detection Engineering Lead

Aj Bell • Manchester

On-site
GBP 90,000 - 120,000
Senior Security Operations Lead - Cloud & Incident Response
Senior Security Operations Lead - Cloud & Incident Response

Manchester Digital • Manchester

Hybrid
GBP 90,000 - 130,000
Security Engineer - Microsoft, SIEM, Sentinel, AlienVault
Security Engineer - Microsoft, SIEM, Sentinel, AlienVault

InfraView Ltd • Manchester

Hybrid
GBP 55,000 - 60,000
Senior Microsoft Security Engineer: Sentinel & Defender
Senior Microsoft Security Engineer: Sentinel & Defender

Experis • Greater London

Hybrid
GBP 90,000 - 120,000
Microsoft Security Engineer
Microsoft Security Engineer

Leap29 • Basildon

On-site
GBP 90,000 - 110,000
Senior SOC Engineer
Senior SOC Engineer

Experis • Greater London

On-site
GBP 90,000 - 120,000
Security Platform Engineer – Microsoft Sentinel & Defender
Security Platform Engineer – Microsoft Sentinel & Defender

BUPA • Salford

Hybrid
GBP 49,000 - 60,000
Bupa health insurance
25 days holiday
Enhanced pension plan and life insurer
+2
Security Engineer - Microsoft Sentinel & Defender XDR
Security Engineer - Microsoft Sentinel & Defender XDR

Netbuilder • City Of London

Hybrid
GBP 47,000 - 87,000
Senior Security Engineer: Microsoft Sentinel & Defender XDR
Senior Security Engineer: Microsoft Sentinel & Defender XDR

Netbuilder • City Of London

Hybrid
GBP 47,000 - 87,000