Senior Security Engineering Consultant

Company: Nomios
Apply for the Senior Security Engineering Consultant
Location: Basingstoke
Job Description:

Overview

As a Senior Security Engineering Consultant, you will design and deliver detection and response capabilities across SIEM, XDR, and SOAR for a diverse client base. You’ll own detection as code, building scalable detections and automations while guiding customer SOC maturity. You work hands-on on detection engineering and advisory tasks, collaborating with SOC engineers and platform teams to improve visibility and coverage. This role offers exposure to modern detection approaches, real-world threat work, and the chance to shape how clients run security operations.

Pay / Benefits

  • competitive salary
  • performance-based bonuses
  • industry-leading benefits
  • office perks (free drinks, breakfast, snacks, lunches, takeaway Fridays)

Responsibilities

  • Design and deliver detections for SIEM and XDR
  • Develop and tune detection logic (KQL or similar)
  • Create MITRE ATT&CK-aligned use cases and coverage mapping
  • Design and implement SOAR automations and playbooks
  • Develop incident response playbooks aligned to detections
  • Maintain detection as code pipelines with versioning
  • Produce technical deliverables including use case catalogs and coverage assessments
  • Collaborate with customers and internal teams to ensure practical, actionable outcomes
  • Lead workshops on detection engineering and SOC maturity
  • Contribute to reusable detection content and validation efforts
  • Identify telemetry gaps and propose improvements

Key requirements

  • Hands-on SIEM engineering experience with detection rule development (Microsoft Sentinel preferred)
  • Experience writing detection logic in KQL or similar
  • Proven SOAR automation and playbook design (Logic Apps, Cortex XSOAR or similar)
  • Scripting/automation with Python or PowerShell and API work
  • Detection use cases aligned to MITRE ATT&CK
  • Understanding of log source mapping to attack lifecycle
  • Experience with XDR/EDR platforms (Microsoft Defender, CrowdStrike, Cortex)
  • Cloud security telemetry experience, especially Azure
  • Customer-facing or consultancy experience
  • Strong communication skills
  • Collaborative
  • Clear communication
  • Customer-facing professionalism
  • SIEM/XDR platforms (Microsoft Sentinel, Defender, Palo Alto XSIAM, CrowdStrike, SentinelOne)
  • SOAR development and playbook design (XSOAR, Logic Apps)
  • KQL or equivalent query languages

…

Posted: September 26th, 2026