SOC Analyst (SC Cleared)
SC Cleared Microsoft Sentinel Detection Engineer - £500/day via Umbrella - Short Term Contract - Remote - Immediate Start - SCC Flex Contract
We're looking for an experienced SC Cleared SOC Analyst/Detection Engineer to support the delivery of a prioritised detection engineering backlog across AWS, Azure, Microsoft 365, Defender XDR, Dynatrace, and ServiceNow environments.
Key Responsibilities
- Own assigned Microsoft Sentinel detection engineering use cases from inception through to production deployment.
- Design, develop and maintain Microsoft Sentinel Analytics Rules, Scheduled Rules, Near Real Time (NRT) Rules and Fusion detection capabilities.
- Create, optimise and maintain Kusto Query Language (KQL) based detections aligned to relevant MITRE ATT&CK tactics, techniques and procedures (TTPs).
- Develop and implement detection logic using data from Defender XDR, Microsoft 365, Azure, AWS CloudTrail, Dynatrace, ServiceNow and other integrated Sentinel connectors.
- Create advanced behavioural detections to identify credential compromise, account takeover, privilege escalation, persistence, lateral movement, defence evasion, command and control activity and data exfiltration.
- Design and implement correlation logic across multiple telemetry sources to improve detection fidelity and reduce alert fatigue.
- Develop and maintain Sentinel Watchlists, Entity Mappings, Automation Rules and Logic App integrations where required.
- Validate detection effectiveness through structured testing, attack simulation, purple team exercises and adversary emulation activities.
- Perform detection tuning and optimisation activities to minimise false positives and improve operational effectiveness.
- Support security monitoring maturity initiatives through continuous enhancement of Sentinel content and use cases.
- Produce high-quality technical documentation including detection logic, implementation details, testing outcomes and operational support procedures.
- Deliver knowledge transfer sessions and operational handovers to SOC Analysts, Security Engineers and Detection Engineering teams.
- Work closely with Threat Intelligence, Security Operations, Incident Response and Security Architecture teams to improve detection coverage and threat visibility.
- Support incident investigations through detection enhancement and rapid development of new Sentinel content to address emerging threats.
- Participate in technical workshops, backlog grooming, sprint planning and governance activities.
- Deliver assigned use cases in line with agreed priorities, quality standards and delivery milestones.
Technical Requirements
- Proven hands-on experience with Microsoft Sentinel.
- Strong Kusto Query Language (KQL) development expertise.
- Experience creating and managing Sentinel Analytics Rules, Hunting Queries, Fusion Rules and Automation Rules.
- Strong knowledge of Microsoft Defender XDR, including Defender for Endpoint, Defender for Identity, Defender for Cloud Apps and Defender for Office 365.
- Experience ingesting and analysing security telemetry from Azure, Microsoft 365, AWS, Syslog, CEF and custom data sources.
- Knowledge of MITRE ATT&CK framework and detection engineering best practices.
- Experience tuning SIEM detections and reducing false positives within enterprise environments.
- Understanding of attack methodologies, adversary behaviours and modern threat actor techniques.
- Familiarity with Sentinel Content Hub solutions, Data Connectors and SOAR integrations.
- Experience with Logic Apps and security automation is advantageous.
If you are a Microsoft Sentinel Detection Engineer looking to make an impact in a fast-paced environment, apply today - professional references required.
NOTE: At SCC, we take the privacy and security of your information very seriously. Any information we hold will be handled in accordance with current data protection legislation. Upon submitting your application, SCC will process your information in line with our privacy policy, which can be found on our website under Legal Privacy Notice Flexible Resourcing.