Senior SOC Engineer

Experis Uk โ€” United Kingdom ยท Posted ~2 hours ago

๐Ÿ”“ Log in to save this job, tailor your resume & track your apply process โ€” 7 days free, no card needed.

Log in to add to target list

Description

Senior SecOps Engineer - Microsoft Security UK | Predominantly Remote | Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities Will Include Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDREngineering and optimisation of SIEM capabilities across enterprise environmentsDeveloping and tuning KQL queries, analytics and detection rulesDesigning and implementing SOC automation, playbooks and scriptingImproving security event detection and response capabilitiesConducting Microsoft tenant health checks, security audits and architecture reviewsAnalysing cloud security risks and recommending appropriate security controlsSupporting complex incident triage and resolutionDesigning and documenting security engineering standards and processesResearching and implementing new Microsoft security capabilitiesProducing high-quality technical and customer-facing documentationWorking directly with customers and technical stakeholdersSupporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure SentinelMicrosoft Defender / Defender XDRStrong KQL / Kusto Query Language capabilitySecurity Engineering, SOC Engineering or Microsoft Security ConsultingSIEM engineering rather than solely alert monitoring or incident triageDetection engineering and security monitoring optimisationAutomation, scripting, SOAR or Sentinel playbooksCloud security assessments, controls and risk analysisDesigning and documenting security processesCustomer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft PurviewMicrosoft Defender for EndpointDefender for CloudDefender for IdentityDefender for Office 365Microsoft Entra IDIntuneAzure security architectureLogic Apps / Sentinel playbooksPowerShell or PythonMITRE ATT&CKMicrosoft Security architecture and tenant assessments Previous experience working directly for Microsoft, or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft Certifications Are Strongly Preferred, Particularly SC-200 - Microsoft Security Operations AnalystAZ-500 - Azure Security Engineer AssociateAZ-104 - Azure Administrator AssociateAZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering, email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.