SOC Engineer Detection
Shape the Future of Microsoft Sentinel Detection Engineering. Are you passionate about Microsoft Sentinel, KQL and building high-quality detections that help a SOC identify threats effectively? We''re looking for a Senior Detection Engineer to join our growing Aerospace, Defence and Security business. You''ll play a key role in designing, developing, testing and improving detection content in Microsoft Sentinel, translating threat behaviours and security requirements into reliable analytics. This is an opportunity to join the Detection Engineering team and help strengthen detection coverage, reduce false positives and ensure detection content remains accurate, performant and operationally useful. As a Senior Detection Engineer, you''ll own detection use cases through their lifecycle, from research and data validation through KQL development, testing, deployment, tuning and continuous improvement. Hybrid: Farnborough 3 days per week, 2 days home based. SC Cleared or eligible. What You''ll Be Doing: Design, develop and maintain Microsoft Sentinel analytics rules using KQL. Translate threat intelligence, attacker behaviours and operational requirements into measurable detection use cases. Map detection content to the MITRE ATTandCK framework and help identify gaps in detection coverage. Validate required log sources, schemas and field mappings before developing detection logic. Test detections against representative data and document expected results, limitations and ..... full job details .....
Other jobs of interest...
Perform a fresh search...
-
Create your ideal job search criteria by
completing our quick and simple form and
receive daily job alerts tailored to you!