Senior Security Engineering Consultant
70000 - 80000 per annum + bonusBasingstoke, England
Permanent
Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands-on technical position within the Security Operations domain, focused on helping customers improve and automate their SOC functions, tooling, and detection capabilities.
Key Responsibilities:
Design and deliver detection rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases to assess coverage and identify gapsDesign and implement SOAR automations, integrations and response workflowsDevelop and document customer incident response playbooks aligned to detection outputsTranslate threat intelligence and operational learnings into improved detections and automationsDeliver detection as code pipelines, including structured use case development and versioning approachesProduce clear technical and customer-facing deliverables, including detection strategies, use case catalogues and coverage assessmentsWork directly with customers as a trusted technical consultantLead workshops covering detection engineering, use case design and SOC maturityGuide customers on improving detection coverage and aligning to MITRE ATT&CKClearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholdersWork closely with platform onboarding and engineering teams to ensure smooth integration of delivered detections and automationsSupport SOC teams by ensuring delivered outputs are practical, usable and aligned to operational workflowsContribute to the continuous evolution of detection use cases, playbooks and automation patternsSupport development of reusable detection content and delivery standardsContribute to lab work, testing and validation of detection approachesIdentify gaps in telemetry, logging and enrichment, and provide recommendations to strengthen detection outcomesJob Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferredExperience writing detection logic using KQL or similar query languagesProven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similarScripting and automation capability using Python, PowerShell or similar, including working with APIsExperience designing detection use cases aligned to MITRE ATT&CKStrong understanding of detection coverage and how log sources map to the attack lifecycleExperience with XDR or EDR platforms such as Microsoft Defender, CrowdStrike or CortexUnderstanding of cloud environments, particularly Azure, and associated security telemetryExperience working in customer-facing or consultancy rolesStrong communication skills, with the ability to explain technical concepts clearlyTechnical Competencies: SIEM and XDR platforms, including Microsoft Sentinel, Microsoft Defender, Palo Alto XSIAM or XDR, CrowdStrike and SentinelOneSOAR development, including automation and playbook design using platforms such as Palo Alto XSOAR or similarScripting and integration using Python, PowerShell or similar, including API-driven automationDetection engineering aligned to MITRE ATT&CK, including use case design, ruleset development and coverage assessmentLog source mapping and normalisation to support detection use casesNetwork Detection and Response technologies such as Vectra AI, Corelight or similarCloud security and telemetry, particularly within Azure environmentsThreat intelligence integration and enrichment to support detection and responseDevelopment of customer playbooks and response workflows aligned to SOC operationsGeneral awareness of emerging technologies, including AI-driven security tooling and their application within detection and responseJob Specifics:
Location:
This is a hybrid role, primarily remote but with a requirement of ad-hoc travel to customer sites and attend the Basingstoke office as required to support delivery, workshops and engagements.
Hours: Full-time, Monday - Friday, 9:00am - 5:30pm. There is no on-call requirement for this position.
Benefits:
Salary up to 80,000 Performance-based bonusesIndustry-leading benefitsA collaborative engineering environmentExposure to real-world threats and modern detection approachesOpportunity to shape Security Operations capabilitiesIf you are a skilled Security Engineering Consultant looking to join a dynamic and impactful team, we encourage you to apply now and be a part of building a secure and connected future with our client.