detection engineering, technical investigation and incident response. This is a hands‐on technical role responsible for the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate. The role would particularly suit an experienced detection engineering, security operations, red‐team, purple‐team or offensive‐security leader … security monitoring, SIEM engineering, detection engineering and incident response within a complex enterprise environment. A strong record of designing, building, operating and evolving Microsoft Sentinel as a production security monitoring and response capability. Deep expertise in KQL and the engineering of analytics rules, hunting queries, workbooks and threat‐informed detection ...