Security Engineer - Microsoft Sentinel & Defender XDR

Netbuilder

City Of London

Hybrid

GBP 47,000 - 87,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

NETbuilder is hiring a London-based, hybrid Security Engineer to develop and maintain detections within Microsoft Sentinel and Defender XDR. You will design logging pipelines, onboard data sources, and optimise KQL queries to identify suspicious activity, while mentoring others and delivering complex security initiatives.

The role requires deep expertise in Azure, Defender XDR and advanced KQL, with experience leading platform migrations and multi-environment security architectures.

Qualifications

  • Experience in Security Engineering, Detection Engineering, SOC Engineering or a similar cyber security role.
  • Hands–on experience with Microsoft Sentinel, Defender XDR and Intune.
  • Strong understanding of SIEM, logging architecture, detection engineering and endpoint security.
  • Experience with KQL and PowerShell and/or Python.
  • Knowledge of MITRE ATT&CK and security monitoring best practices.
  • Experience onboarding data sources, tuning detections and improving detection coverage.
  • Ability to work independently, take ownership of deliverables and solve problems proactively.
  • Extensive experience designing and implementing enterprise–scale security monitoring and detection capabilities.
  • Deep expertise in Microsoft Sentinel, Defender XDR and advanced KQL.
  • Experience designing logging architectures and producing technical designs/LLDs.
  • Proven experience leading security platform migrations and transformation programmes.
  • Strong understanding of Azure, AWS and multi–environment security architectures.
  • Ability to independently define architectural direction, make technical decisions and lead complex initiatives.
  • Experience mentoring engineers and engaging with stakeholders at all levels.
  • Ability to commute to London or plan to relocate before starting work.
  • Work authorisation in the United Kingdom.

Responsibilities

  • Develop, test and maintain detections within Microsoft Sentinel and Defender XDR.
  • Write and optimise KQL queries to identify suspicious activity and security events.
  • Design and implement logging pipelines and onboard data sources into Sentinel.
  • Define logging requirements, collection methods and ingestion approaches.
  • Analyse telemetry to identify gaps in data quality, coverage and detection capability.
  • Tune detections, reduce false positives and improve monitoring effectiveness.
  • Translate threat intelligence into practical detection use cases.
  • Work with SOC, Threat Hunting and Incident Response teams to improve outcomes.
  • Use PowerShell or Python to automate processes and improve efficiency.
  • Independently manage and deliver assigned workstreams.
  • Lead the onboarding and integration of complex environments into the wider security architecture.
  • Design target–state logging, monitoring and detection architectures.
  • Produce Low–Level Designs (LLDs) and technical documentation.
  • Lead migrations from platforms such as Splunk and CrowdStrike to Microsoft Sentinel and Defender.
  • Design centralised and multi–tenant logging solutions across Microsoft and AWS environments.
  • Establish logging and security foundations where capabilities are immature or inconsistent.
  • Drive improvements in detection maturity, monitoring coverage and security posture.
  • Provide technical leadership, mentoring and architectural guidance.
  • Operate with significant autonomy, making key technical decisions and driving delivery across complex environments.

Skills

Security engineering
Threat detection
Incident response
SOC engineering
Azure security

Tools

KQL
PowerShell
Python

Job description

Salary: GBP47,000 – 87,000 per year

Requirements:
  • Experience in Security Engineering, Detection Engineering, SOC Engineering or a similar cyber security role.
  • Hands–on experience with Microsoft Sentinel, Defender XDR and Intune.
  • Strong understanding of SIEM, logging architecture, detection engineering and endpoint security.
  • Experience with KQL and PowerShell and/or Python.
  • Knowledge of MITRE ATT&CK and security monitoring best practices.
  • Experience onboarding data sources, tuning detections and improving detection coverage.
  • Ability to work independently, take ownership of deliverables and solve problems proactively.
  • Extensive experience designing and implementing enterprise–scale security monitoring and detection capabilities.
  • Deep expertise in Microsoft Sentinel, Defender XDR and advanced KQL.
  • Experience designing logging architectures and producing technical designs/LLDs.
  • Proven experience leading security platform migrations and transformation programmes.
  • Strong understanding of Azure, AWS and multi–environment security architectures.
  • Ability to independently define architectural direction, make technical decisions and lead complex initiatives.
  • Experience mentoring engineers and engaging with stakeholders at all levels.
  • Ability to commute to London or plan to relocate before starting work.
  • Work authorisation in the United Kingdom.
Responsibilities:
  • Develop, test and maintain detections within Microsoft Sentinel and Defender XDR.
  • Write and optimise KQL queries to identify suspicious activity and security events.
  • Design and implement logging pipelines and onboard data sources into Sentinel.
  • Define logging requirements, collection methods and ingestion approaches.
  • Analyse telemetry to identify gaps in data quality, coverage and detection capability.
  • Tune detections, reduce false positives and improve monitoring effectiveness.
  • Translate threat intelligence into practical detection use cases.
  • Work with SOC, Threat Hunting and Incident Response teams to improve outcomes.
  • Use PowerShell or Python to automate processes and improve efficiency.
  • Independently manage and deliver assigned workstreams.
  • Lead the onboarding and integration of complex environments into the wider security architecture.
  • Design target–state logging, monitoring and detection architectures.
  • Produce Low–Level Designs (LLDs) and technical documentation.
  • Lead migrations from platforms such as Splunk and CrowdStrike to Microsoft Sentinel and Defender.
  • Design centralised and multi–tenant logging solutions across Microsoft and AWS environments.
  • Establish logging and security foundations where capabilities are immature or inconsistent.
  • Drive improvements in detection maturity, monitoring coverage and security posture.
  • Provide technical leadership, mentoring and architectural guidance.
  • Operate with significant autonomy, making key technical decisions and driving delivery across complex environments.
Technologies:
  • AWS
  • Azure
  • Support
  • PowerShell
  • Python
  • Security
  • Splunk
  • Cloud
More:

We are a London–based team working in a hybrid model, offering a salary dependent on experience. NETbuilder brings decades of experience and deep expertise in the digital landscape, and we are building something genuinely new within the NETbuilder group. You will join a world–class team of experienced consultants with full support, resources and backing to help shape and deliver our security monitoring and detection capabilities across Microsoft security platforms.

last updated 39 week of 2026

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer: Microsoft Sentinel & Defender XDR
Senior Security Engineer: Microsoft Sentinel & Defender XDR

Netbuilder • City Of London

Hybrid
GBP 47,000 - 87,000
Security Engineer - Systems Integrator
Security Engineer - Systems Integrator

Hamilton Barnes Associates Limited • Greater London, Cardiff

On-site
GBP 41,000 - 50,000
Primarily remote work
Occasional office attendance (London /
Client-facing responsibilities
Security Engineer
Security Engineer

Hamilton Barnes ? • Cardiff

On-site
GBP 38,000 - 52,000
Security Engineer
Security Engineer

LT Harper Group • Greater London

Hybrid
GBP 70,000 - 115,000
Security engineer
Security engineer

Tria • Cardiff

Hybrid
GBP 45,000 - 55,000
Remote work flexibility
Security Consultant
Security Consultant

Consult • Greater London

Hybrid
GBP 55,000 - 70,000
Security engineer in City
Security engineer in City

Tria • City

Hybrid
GBP 45,000 - 55,000
Microsoft Security Engineer
Microsoft Security Engineer

Leap29 • Basildon

On-site
GBP 90,000 - 110,000
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Southampton

Hybrid
GBP 72,000 - 88,000
Performance-based bonuses
Collaborative engineering environment
Industry-leading benefits
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

On-site
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work