Senior Security Engineering Consultant

Infosec

Basingstoke

Hybrid

GBP 56,000 - 80,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Salary up to £80,000
Bonuses
Hybrid work

Job summary

Infosec is seeking a Senior Security Engineering Consultant for a hands-on, technical role in the Security Operations domain. You will design and deliver detection rules across SIEM/XDR, tune logic with KQL, and align use cases to MITRE ATT&CK.

You will also implement SOAR automations and incident response playbooks for customer engagements. The role is hybrid in the UK with ad-hoc travel to customer sites and occasional visits to the Basingstoke area.

Qualifications

  • +Hands-on SIEM engineering with rule tuning; Microsoft Sentinel preferred.
  • +Experience designing SOAR automations and playbooks (e.g., Logic Apps, XSOAR).
  • +Scripting in Python/PowerShell with API integration.
  • +Design detection use cases aligned to MITRE ATT&CK.

Responsibilities

  • Design and deliver detection rulesets across SIEM and XDR platforms.
  • Develop and tune detection logic using KQL or equivalent query languages.
  • Design detection use cases aligned to MITRE ATT&CK and real-world techniques.
  • Map customer log sources to detection use cases and identify gaps.
  • Design and implement SOAR automations, integrations and response workflows.
  • Develop and document incident response playbooks aligned to detections.

Skills

SIEM engineering
SOAR automation
Python scripting
KQL / detection logic
MITRE ATT&CK
Customer-facing
Azure cloud security
Communication

Tools

Logic Apps
Cortex XSOAR
Palo Alto XSOAR
Microsoft Sentinel
CrowdStrike
Vectra AI
Corelight

Job description

Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands‑on technical position within the Security Operations domain, focused on helping customers improve and automate their SOC functions, tooling, and detection capabilities.

Key Responsibilities
  • Design and deliver detection rulesets across SIEM and XDR platforms
  • Develop and tune detection logic using KQL or equivalent query languages
  • Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques
  • Map customer log sources to detection use cases to assess coverage and identify gaps
  • Design and implement SOAR automations, integrations and response workflows
  • Develop and document customer incident response playbooks aligned to detection outputs
  • Translate threat intelligence and operational learnings into improved detections and automations
  • Deliver detection as code pipelines, including structured use case development and versioning approaches
  • Produce clear technical and customer‑facing deliverables, including detection strategies, use case catalogues and coverage assessments
  • Work directly with customers as a trusted technical consultant
  • Lead workshops covering detection engineering, use case design and SOC maturity
  • Guide customers on improving detection coverage and aligning to MITRE ATT&CK
  • Clearly explain detection strategies, gaps and recommendations to both technical and non‑technical stakeholders
  • Work closely with platform onboarding and engineering teams to ensure smooth integration of delivered detections and automations
  • Support SOC teams by ensuring delivered outputs are practical, usable and aligned to operational workflows
  • Contribute to the continuous evolution of detection use cases, playbooks and automation patterns
  • Support development of reusable detection content and delivery standards
  • Contribute to lab work, testing and validation of detection approaches
  • Identify gaps in telemetry, logging and enrichment, and provide recommendations to strengthen detection outcomes
Job Requirements
  • Strong hands‑on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred
  • Experience writing detection logic using KQL or similar query languages
  • Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar
  • Scripting and automation capability using Python, PowerShell or similar, including working with APIs
  • Experience designing detection use cases aligned to MITRE ATT&CK
  • Strong understanding of detection coverage and how log sources map to the attack lifecycle
  • Experience with XDR or EDR platforms such as Microsoft Defender, CrowdStrike or Cortex
  • Understanding of cloud environments, particularly Azure, and associated security telemetry
  • Experience working in customer‑facing or consultancy roles
  • Strong communication skills, with the ability to explain technical concepts clearly
Technical Competencies
  • SIEM and XDR platforms, including Microsoft Sentinel, Microsoft Defender, Palo Alto XSIAM or XDR, CrowdStrike and SentinelOne
  • SOAR development, including automation and playbook design using platforms such as Palo Alto XSOAR or similar
  • Scripting and integration using Python, PowerShell or similar, including API‑driven automation
  • Detection engineering aligned to MITRE ATT&CK, including use case design, ruleset development and coverage assessment
  • Log source mapping and normalisation to support detection use cases
  • Network Detection and Response technologies such as Vectra AI, Corelight or similar
  • Cloud security and telemetry, particularly within Azure environments
  • Threat intelligence integration and enrichment to support detection and response
  • Development of customer playbooks and response workflows aligned to SOC operations
  • General awareness of emerging technologies, including AI‑driven security tooling and their application within detection and response
Job Specifics
  • Location: This is a hybrid role, primarily remote but with a requirement of ad‑hoc travel to customer sites and attend the Basingstoke office as required to support delivery, workshops and engagements.
  • Hours: Full‑time, Monday - Friday, 9:00am - 5:30pm. There is no on‑call requirement for this position.
Benefits
  • Salary up to 80,000
  • Performance‑based bonuses
  • Industry‑leading benefits
  • A collaborative engineering environment
  • Exposure to real‑world threats and modern detection approaches
  • Opportunity to shape Security Operations capabilities
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer Consultant
Senior Security Engineer Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits
Cyber Security Consultant
Cyber Security Consultant

Franklin Fitch • Greater London

Hybrid
GBP 55,000 - 65,000
Bonus
Senior Detection Engineer for SOC Automation
Senior Detection Engineer for SOC Automation

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
SOC Engineer Detection
SOC Engineer Detection

Sopra Steria Ltd • Farnborough

Hybrid
GBP 55,000 - 60,000
Health Shields
Life assurance
Pension
+2
Senior Security Operational Centre Engineer
Senior Security Operational Centre Engineer

Sopra Steria • Farnborough

Hybrid
GBP 50,000 - 60,000
25 days annual leave
Health Shields
Life assurance
+1
3rd Line Security Analyst
3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 51,000 - 69,000
Senior SOC Analyst
Senior SOC Analyst

GCS Recruitment • Greater London

Hybrid
GBP 90,000 - 120,000
Security Engineer - Systems Integrator
Security Engineer - Systems Integrator

Hamilton Barnes Associates Limited • Greater London, Cardiff

Hybrid
GBP 41,000 - 50,000
Primarily remote work
Occasional office attendance (London /
Client-facing responsibilities
Senior Security Architect
Senior Security Architect

develop • Greater London

Hybrid
GBP 90,000 - 110,000
Up to £110,000 salary
Benefits package
Remote or hybrid working
Senior SOC Engineer
Senior SOC Engineer

Sopra Steria Ltd • Farnborough

Hybrid
GBP 68,000 - 92,000
25 days annual leave
Life Insurance
Pension
+3