Cloud People
Microsoft Sentinel Detection Engineer (Contract)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Microsoft Sentinel Detection Engineer
💰 £500 to £550 per day DOE, outside IR35
📍 Hybrid, London two days per week
Company & Role
A specialist Microsoft security partner with its own managed detection and response service is bringing in contract engineers to support a large enterprise security programme. It is an initial contract running roughly November to March, with starts targeted within around three weeks.
This role owns the SIEM, both the platform and the content running on it. You will be the Microsoft Sentinel and detection engineering expert, improving telemetry, building high fidelity detections and automating the monitoring capability for a proactive security function. You will work closely with Security Operations, Infrastructure, Cloud and Application teams.
Why This Role Stands Out
- Proper detection engineering. Detection as Code, CI/CD and peer review, not just tuning someone else's rules.
- Ownership of both platform and content, so you shape how the whole monitoring capability works.
- Meaty telemetry work, from Data Collection Rules and custom parsers through to API integrations and ingestion optimisation.
- Outside IR35 with a defined initial term, and a team that wants to move fast.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Key Responsibilities
- Act as the subject matter expert for Microsoft Sentinel, detection engineering and security monitoring architecture.
- Design, test, deploy and tune analytics rules, correlation logic and hunting queries aligned to MITRE ATT&CK.
- Engineer data connectors, ingestion pipelines, Data Collection Rules, custom parsers, custom tables and API integrations.
- Set logging standards, onboarding patterns and governance across the detection engineering lifecycle.
- Build automation with Logic Apps, Azure Functions, REST APIs, PowerShell and Python.
- Integrate endpoint, identity, cloud, network and infrastructure controls with Sentinel and the Defender ecosystem.
- Build workbooks, dashboards, platform health monitoring and KPI reporting.
- Produce high and low level designs and engineering standards, and lead upgrades, migrations and proof of concepts, including planned out of hours support for major changes.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Ideal Experience
- Proven SIEM, detection or security platform engineering in a large enterprise environment.
- Advanced Microsoft Sentinel, covering architecture, KQL, analytics rules, hunting, workbooks, watchlists and playbooks.
- Strong Defender XDR across Endpoint, Identity and Cloud.
- Telemetry onboarding with Azure Monitor Agent, Azure Arc, Data Collection Rules, Log Analytics and custom ingestion.
- Windows Event Forwarding, XPath filtering, Sysmon and PowerShell logging.
- Detection as Code using Azure DevOps or Git based CI/CD, Infrastructure as Code concepts and ideally tools such as Cribl.
- Automation with PowerShell, Python and REST APIs.
- SC 200 or AZ 500 desirable.
If you are the person who builds the detections other analysts rely on and you enjoy making a SIEM genuinely better, this is one to look at.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location