Enable job alerts via email!

Senior Microsoft Sentinel / SIEM Engineer

JR United Kingdom

Basingstoke

Remote

GBP 85,000

Full time

6 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading global security Microsoft partner seeks a Microsoft Sentinel expert to handle enterprise-wide log onboarding, optimizing threat detection and response efforts. This fully remote role offers deep organizational involvement in nation-state attack detection while providing career progression in a highly flexible work culture.

Benefits

Direct access to Microsoft Sentinel product teams
Deep involvement in nation-state attack detection
Recognition and career progression

Qualifications

  • Experience building and integrating complex Microsoft Sentinel.
  • Understanding of security telemetry across multiple layers.
  • Scripting and engineering skills, particularly Python and PowerShell.

Responsibilities

  • Own and optimise log onboarding to Microsoft Sentinel.
  • Enhance ingestion pipelines and contribute to detection capabilities.
  • Partner with IR teams on tuning rules against live threat actor activity.

Skills

Log ingestion
Cyber threat detection
Custom Function Apps
Security telemetry
Incident response
Python
PowerShell

Job description

Social network you want to login/join with:

col-narrow-left

Client:

Cloud Decisions

Location:
Job Category:

Other

-

EU work permit required:

Yes

col-narrow-right

Job Views:

3

Posted:

31.05.2025

Expiry Date:

15.07.2025

col-wide

Job Description:

Job Title:

To £85,000 + Benefits + Microsoft

Fully Remote, UK

(*Global Microsoft Managed MISA Partner

+ complex Sentinel Engineering/Integration)

The Opportunity

This is a standout opportunity for a Microsoft Sentinel expert to step into a high-impact, technically advanced role with a global security Microsoft powerhouse.

You'll be joining a Microsoft managed global partner, a prominent MISA member, a team with Security MVP's and a Microsoft Verified Safe XDR Solution Partner, and a trusted Security Depth Partner.

In short giving you unparalleled access to Microsoft’s security product roadmap, security previews, and frontline support.

You'll work at the sharp end of cyber defence, directly contributing to investigations involving nation-state threat actors (including IR, CH, and NK based campaigns) while refining your craft across enterprise-scale log ingestion and customised Sentinel integration engineering that will stretch your skills, give you opportunity to ingest complex logs from a mass of cloud and data sources and the chance to learn these as you go.

The Role

You'll own and optimise enterprise-wide log onboarding into Microsoft Sentinel – deploying standard and custom connectors, Function Apps, and parsers to build tailored SIEM solutions that drive real-world threat detection and response.

  • Log ingestion at scale across numerous hybrid and multi-cloud environments
  • Enhance custom Function Apps and ingestion pipelines
  • Parse, normalise, and optimise log telemetry to ensure precision and cost control
  • Partner with IR teams on real attacks – tuning rules against live threat actor activity
  • Sync closely with Microsoft teams to build cutting-edge detection capabilities
  • Contribute to internal knowledge base and help shape engineering standards

What's needed?

  • Experience building and integrating complex Microsoft Sentinel at SMC and enterprise
  • Understanding of security telemetry across identity, endpoint, cloud, and network layers
  • Experience in SIEM content development, including KQL, analytics rules, and custom data connectors
  • Scripting and engineering skills – Python, PowerShell, APIs, Function Apps
  • A background in cyber threat detection, incident response or DFIR is a real plus
  • Comfortable working in very fast-moving, customer facing delivery environments

The Technical Shizzle:

  • PowerShell, Python, REST APIs
  • Log ingestion and parsing across multi platforms (Azure/AWS/GCP, M365, Defender, Entra, Copilot, Carbon Black, Okta + Tier 1 Network vendors)
  • MITRE ATT&CK, threat detection frameworks, IOC enrichment
  • Ability to go and work things out is crucial
  • Sentinel/Log Analytics Cost Management and Data Optimisation

What’s In It for You?

  • Direct access to Microsoft Sentinel product teams and early feature previews
  • Deep involvement in real-world nation-state attack detection
  • Huge opportunity to stretch and sharpen you Sentinel mastery
  • Be part of a Microsoft Security elite MISA and Depth partner
  • Exposure to multi-cloud detection and advanced security automation
  • Fully remote, highly flexible work culture with global team collaboration
  • Recognition, career progression and growth all within a global Microsoft specialist and respected security consultancy
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Microsoft Sentinel / SIEM Engineer

JR United Kingdom

Hemel Hempstead

Remote

GBP 70,000 - 100,000

4 days ago
Be an early applicant

Senior Microsoft Sentinel / SIEM Engineer

JR United Kingdom

Lincoln

Remote

GBP 60,000 - 90,000

4 days ago
Be an early applicant