Senior SOC Engineer

Experis

Greater London

On-site

GBP 90,000 - 120,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Experis partners with a specialist Microsoft Security organisation to appoint two Senior SecOps Engineers. The role is UK-based with predominantly remote work and occasional presence in London, offering a permanent position in a growing Microsoft Cyber Engineering team.

You will design, implement and optimise Microsoft Sentinel and Defender solutions, engineering SIEM capabilities and developing detection rules for large enterprise environments. Strong hands-on security engineering is essential.

Qualifications

  • Microsoft Sentinel / Azure Sentinel experience in enterprise environments.
  • Microsoft Defender / Defender XDR engineering and deployments.
  • Strong KQL / Kusto query language capabilities.
  • Hands-on Security/SOC engineering, not just monitoring.

Responsibilities

  • Design, implement and support Microsoft Sentinel and Defender solutions.
  • Engineer and optimise SIEM capabilities across enterprise environments.
  • Develop and tune detection rules and analytics with KQL.
  • Design SOC automation, playbooks and scripting.
  • Improve security event detection and response capabilities.
  • Conduct tenant health checks, security audits and architecture reviews.
  • Support incident triage and resolution for complex engagements.
  • Document security engineering standards and processes.

Skills

Microsoft Sentinel
Defender XDR
KQL / Kusto
Security Engineering
SOC Engineering
Automation / SOAR / Playbooks
Cloud security assessments
Customer-facing delivery
PowerShell / Python scripting

Job description

Senior SecOps Engineer - Microsoft Security

UK | Predominantly Remote | Occasional presence in London

Permanent

We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team.

This is not a traditional SOC Analyst position.

We are looking for technically strong Microsoft Security Engineers with genuine hands‑on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments.

The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands‑on with complex customer environments.

The Role

Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions.

Responsibilities will include:

  • Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR
  • Engineering and optimisation of SIEM capabilities across enterprise environments
  • Developing and tuning KQL queries, analytics and detection rules
  • Designing and implementing SOC automation, playbooks and scripting
  • Improving security event detection and response capabilities
  • Conducting Microsoft tenant health checks, security audits and architecture reviews
  • Analysing cloud security risks and recommending appropriate security controls
  • Supporting complex incident triage and resolution
  • Designing and documenting security engineering standards and processes
  • Researching and implementing new Microsoft security capabilities
  • Producing high‑quality technical and customer‑facing documentation
  • Working directly with customers and technical stakeholders
  • Supporting and mentoring more junior members of the engineering team
Essential Experience

To be considered, you should have strong commercial experience across the following:

  • Microsoft Sentinel / Azure Sentinel
  • Microsoft Defender / Defender XDR
  • Strong KQL / Kusto Query Language capability
  • Security Engineering, SOC Engineering or Microsoft Security Consulting
  • SIEM engineering rather than solely alert monitoring or incident triage
  • Detection engineering and security monitoring optimisation
  • Automation, scripting, SOAR or Sentinel playbooks
  • Cloud security assessments, controls and risk analysis
  • Designing and documenting security processes
  • Customer‑facing technical deliveryCandidates whose experience is predominantly L1/L2 SOC monitoring without hands‑on Sentinel and Defender engineering are unlikely to be suitable for this position.
Highly Desirable

Experience across any of the following would be particularly valuable:

  • Microsoft Purview
  • Microsoft Defender for Endpoint
  • Defender for Cloud
  • Defender for Identity
  • Defender for Office 365
  • Microsoft Entra ID
  • Intune
  • Azure security architecture
  • Logic Apps / Sentinel playbooks
  • PowerShell or Python
  • MITRE ATT&CK
  • Microsoft Security architecture and tenant assessmentsPrevious experience working directly for Microsoft, or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous.
Microsoft Certifications

Relevant Microsoft certifications are strongly preferred, particularly:

  • SC-200 - Microsoft Security Operations Analyst
  • AZ-500 - Azure Security Engineer Associate
  • AZ-104 - Azure Administrator Associate
  • AZ-305 - Azure Solutions Architect Expert

Equivalent or additional Microsoft Security certifications will also be considered.

The Opportunity

This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function.

You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development.

The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands‑on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Microsoft Security Engineer
Microsoft Security Engineer

Leap29 • Basildon

On-site
GBP 90,000 - 110,000
Security Engineer
Security Engineer

IntaPeople: STEM Recruitment • Cardiff

Hybrid
GBP 55,000 - 85,000
Hybrid working
Training & certifications
Exposure to client environments
+2
Senior Security Architect
Senior Security Architect

develop • Greater London

Hybrid
GBP 90,000 - 110,000
Up to £110,000 salary
Benefits package
Remote or hybrid working
Senior SOC Engineer in Cardiff
Senior SOC Engineer in Cardiff

Fazer Recruitment • Cardiff

Hybrid
GBP 63,000 - 77,000
Two paid trips per month to Basingstoe
Senior Security Consultant
Senior Security Consultant

ITC Secure • Greater London

Hybrid
GBP 70,000 - 90,000
25 days annual leave
Private health insurance
Enhanced maternity and paternity leave
+2
Junior Security Engineer
Junior Security Engineer

Cybanetix • Greater London

On-site
GBP 50,000 - 70,000
Hands-on experience with modern SIEM, EDR, and Azure security tooling
Structured progression into security engineering
Mentorship from senior engineers and architects
Senior Microsoft Security Engineer: Sentinel & Defender
Senior Microsoft Security Engineer: Sentinel & Defender

Experis • Greater London

Hybrid
GBP 90,000 - 120,000
3rd Line Security Analyst
3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 51,000 - 69,000
Security Engineer - Microsoft, SIEM, Sentinel, AlienVault
Security Engineer - Microsoft, SIEM, Sentinel, AlienVault

InfraView Ltd • Manchester

Hybrid
GBP 55,000 - 60,000
Head of Security Operations Technology · London, Dubai · Hybrid
Head of Security Operations Technology · London, Dubai · Hybrid

Sokin • Greater London

Hybrid
GBP 120,000 - 180,000