Senior Security Engineering Consultant


Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands-on technical position within the Security Operations domain, focused on helping customers improve and automate their SOC functions, tooling, and detection capabilities.



Key Responsibilities:

  • Design and deliver detection rulesets across SIEM and XDR platforms
  • Develop and tune detection logic using KQL or equivalent query languages
  • Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques
  • Map customer log sources to detection use cases to assess coverage and identify gaps
  • Design and implement SOAR automations, integrations and response workflows
  • Develop and document customer incident response playbooks aligned to detection outputs
  • Translate threat intelligence and operational learnings into improved detections and automations
  • Deliver detection as code pipelines, including structured use case development and versioning approaches
  • Produce clear technical and customer-facing deliverables, including detection strategies, use case catalogues and coverage assessments
  • Work directly with customers as a trusted technical consultant
  • Lead workshops covering detection engineering, use case design and SOC maturity
  • Guide customers on improving detection coverage and aligning to MITRE ATT&CK
  • Clearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholders
  • Work closely with platform onboarding and engineering teams to ensure smooth integration of delivered detections and automations
  • Support SOC teams by ensuring delivered outputs are practical, usable and aligned to operational workflows
  • Contribute to the continuous evolution of detection use cases, playbooks and automation patterns
  • Support development of reusable detection content and delivery standards
  • Contribute to lab work, testing and validation of detection approaches
  • Identify gaps in telemetry, logging and enrichment, and provide recommendations to strengthen detection outcomes


Job Requirements:

  • Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred
  • Experience writing detection logic using KQL or similar query languages
  • Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar
  • Scripting and automation capability using Python, PowerShell or similar, including working with APIs
  • Experience designing detection use cases aligned to MITRE ATT&CK
  • Strong understanding of detection coverage and how log sources map to the attack lifecycle
  • Experience with XDR or EDR platforms such as Microsoft Defender, CrowdStrike or Cortex
  • Understanding of cloud environments, particularly Azure, and associated security telemetry
  • Experience working in customer-facing or consultancy roles
  • Strong communication skills, with the ability to explain technical concepts clearly


Technical Competencies:

  • SIEM and XDR platforms, including Microsoft Sentinel, Microsoft Defender, Palo Alto XSIAM or XDR, CrowdStrike and SentinelOne
  • SOAR development, including automation and playbook design using platforms such as Palo Alto XSOAR or similar
  • Scripting and integration using Python, PowerShell or similar, including API-driven automation
  • Detection engineering aligned to MITRE ATT&CK, including use case design, ruleset development and coverage assessment
  • Log source mapping and normalisation to support detection use cases
  • Network Detection and Response technologies such as Vectra AI, Corelight or similar
  • Cloud security and telemetry, particularly within Azure environments
  • Threat intelligence integration and enrichment to support detection and response
  • Development of customer playbooks and response workflows aligned to SOC operations
  • General awareness of emerging technologies, including AI-driven security tooling and their application within detection and response


Job Specifics:

  • Location: This is a hybrid role, primarily remote but with a requirement of ad-hoc travel to customer sites and attend the Basingstoke office as required to support delivery, workshops and engagements.
  • Hours: Full-time, Monday - Friday, 9:00am - 5:30pm. There is no on-call requirement for this position.


Benefits:

  • Salary up to £80,000
  • Performance-based bonuses
  • Industry-leading benefits
  • A collaborative engineering environment
  • Exposure to real-world threats and modern detection approaches
  • Opportunity to shape Security Operations capabilities


If you are a skilled Security Engineering Consultant looking to join a dynamic and impactful team, we encourage you to apply now and be a part of building a secure and connected future with our client.

Job Details

Company
Infosec
Location
Basingstoke, Hampshire, United Kingdom
Hybrid / Remote Options
Employment Type
Permanent
Salary
£70000 - £80000/annum bonus
Posted