Overview
In this hands-on, senior role, you will strengthen customers’ Security Operations by designing and automating detections across SIEM and XDR, and implementing SOAR-driven responses. You will work as a trusted technical consultant to improve detection coverage, align use cases to MITRE ATT&CK, and guide customers through workshops and best practices. You’ll shape detection content and playbooks, collaborating with onboarding and engineering teams to ensure practical delivery. This role offers real-world threat exposure and the chance to influence SOC maturity and detection workflows.
Pay / Benefits
- Salary up to 80,000
- Performance-based bonuses
- Industry-leading benefits
- Collaborative engineering environment
- Exposure to real-world threats and modern detection approaches
- Opportunity to shape Security Operations capabilities
Responsibilities
- Design and deliver detection rulesets across SIEM and XDR platforms
- Develop and tune detection logic using KQL or equivalent languages
- Design detection use cases aligned to MITRE ATT&CK and real-world techniques
- Map customer log sources to detection use cases to assess coverage
- Design and implement SOAR automations, integrations and response workflows
- Develop and document incident response playbooks aligned to detection outputs
- Translate threat intelligence and operational learnings into improved detections and automations
- Deliver detection as code pipelines with versioning
- Produce technical and customer-facing deliverables like use case catalogues and coverage assessments
- Work directly with customers as a trusted technical consultant
- Lead workshops on detection engineering, use case design and SOC maturity
- Guide customers on improving detection coverage and aligning to MITRE ATT&CK
- Explain detection strategies, gaps and recommendations to both technical and non-technical stakeholders
- Collaborate with platform onboarding and engineering teams for smooth integration of detections and automations
- Support SOC teams to ensure outputs are practical and aligned to workflows
- Contribute to evolution of detection use cases, playbooks and automation patterns
- Support development of reusable detection content and delivery standards
- Contribute to lab work, testing and validation of detection approaches
- Identify telemetry gaps and recommend improvements to strengthen detection outcomes
Key requirements
- Hands-on SIEM engineering experience with detection rule development and tuning (Microsoft Sentinel preferred)
- Experience writing detection logic using KQL or similar
- Proven design and implementation of SOAR automations and playbooks (Logic Apps, Cortex XSOAR or similar)
- Scripting/automation using Python or PowerShell including API work
- Experience designing detection use cases aligned to MITRE ATT&CK
- Strong understanding of detection coverage and log source mapping to attack lifecycle
- Experience with XDR/EDR platforms (Microsoft Defender, CrowdStrike, Cortex)
- Azure/cloud telemetry understanding
- Customer-facing or consultancy experience
- Strong communication skills to explain technical concepts clearly
- Technical competencies in SIEM/XDR platforms and automation tooling
- Threat intelligence integration and enrichment experience
- Awareness of emerging security tooling including AI-driven threats
- Clear communication
- Consultancy mindset
- Cross-functional collaboration
- Microsoft Sentinel
- KQL
- SOAR platforms (Logic Apps, Cortex XSOAR, Palo Alto XSOAR)
…
