Remote UK: Threat Detection Content Engineer

BlueVoyant

United Kingdom

Remote

GBP 75,000 - 120,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

BlueVoyant is seeking a Security Content Engineer to own and enhance detection content for the Microsoft Sentinel environment, including tuning for efficiency and reducing false positives. You will research emerging threats and design proactive detection strategies while developing scalable automation for key workflows.

Ideal candidates will have 5-8 years in detection engineering or related roles, with deep expertise in Microsoft Sentinel, 365 Defender, Logic Apps, and strong KQL skills.

Qualifications

  • 5-8 years of direct experience in Detection Engineering, Security Operations or similar content-creation role.
  • Hands-on expertise with the Microsoft security stack: Microsoft Sentinel, Microsoft 365 Defender, Logic Apps.
  • High proficiency in Kusto Query Language (KQL) and writing optimized queries for detection/hunting.
  • Strong experience automating security workflows using SOAR platforms, APIs or scripting (Python/PowerShell).
  • Ability to work autonomously, manage priorities, and handle complex projects.

Responsibilities

  • Own and enhance detection content with high-fidelity logic in KQL for Microsoft Sentinel.
  • Perform independent global tuning to reduce alert fatigue and false positives for customers.
  • Lead threat-informed research to design proactive detection strategies.
  • Develop scalable automation for security workflows and incident enrichment.
  • Serve as technical point of contact for clients and collaborate with integration teams.
  • Contribute to evolving security policies and automation frameworks.

Skills

Detection engineering
KQL proficiency
SOAR automation
MITRE ATT&CK knowledge
Log analysis & forensics
Clear communication

Tools

Microsoft Sentinel
Microsoft 365 Defender
Logic Apps

Job description

BlueVoyant is seeking a Security Content Engineer to own and enhance detection content for the Microsoft Sentinel environment, including tuning for efficiency and reducing false positives. You will research emerging threats and design proactive detection strategies while developing scalable automation for key workflows.

Ideal candidates will have 5-8 years in detection engineering or related roles, with deep expertise in Microsoft Sentinel, 365 Defender, Logic Apps, and strong KQL skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Content Engineer: KQL & Sentinel Automation
Detection Content Engineer: KQL & Sentinel Automation

BlueVoyant • Greater London

Hybrid
GBP 70,000 - 100,000
Security Content Engineer
Security Content Engineer

BlueVoyant • Greater London

Hybrid
GBP 70,000 - 100,000
Detection Engineer: Master Microsoft Sentinel & Defender XDR
Detection Engineer: Master Microsoft Sentinel & Defender XDR

Aviva • Bristol

On-site
GBP 39,000 - 65,000
Bonus: 10% of annual salary
Generous pension—Aviva contributes up,
Private medical benefit
+2
Senior Microsoft Security Engineer: Sentinel & Defender
Senior Microsoft Security Engineer: Sentinel & Defender

Experis • Greater London

Hybrid
GBP 90,000 - 120,000
Microsoft Security Engineer
Microsoft Security Engineer

Leap29 • Basildon

On-site
GBP 90,000 - 110,000
Security Engineer - Systems Integrator
Security Engineer - Systems Integrator

Hamilton Barnes Associates Limited • Greater London, Cardiff

Hybrid
GBP 41,000 - 50,000
Primarily remote work
Occasional office attendance (London /
Client-facing responsibilities
Security Engineer
Security Engineer

LT Harper Recruitment Group • Greater London

Hybrid
GBP 75,000 - 110,000
Senior Microsoft Security Architect: Azure & Sentinel
Senior Microsoft Security Architect: Azure & Sentinel

Leap29 • Basildon

On-site
GBP 90,000 - 110,000
Remote UK/Ireland: Senior Microsoft Sentinel Architect
Remote UK/Ireland: Senior Microsoft Sentinel Architect

Company • Greater London

On-site
GBP 90,000 - 120,000
Senior SOC Engineer
Senior SOC Engineer

Experis • Greater London

On-site
GBP 90,000 - 120,000