Rodeo
Get started

NETbuilder

Security Engineer - Microsoft Sentinel & Defender XDR (Various levels)

London
Posted about 14 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

London (Hybrid)

Salary (Dependent on experience)

Security Engineer (Mid-Senior & Senior)

We are seeking Security Engineers to help develop, enhance and mature security monitoring, logging and detection capabilities across Microsoft security platforms. Working with Microsoft Sentinel, Microsoft Defender XDR, KQL and automation technologies, you will play a key role in improving detection coverage, onboarding data sources and strengthening enterprise security monitoring.

We are recruiting for both Mid-Senior Security Engineer and Senior Security Engineer positions. Both roles require a high degree of autonomy and ownership, with individuals expected to identify challenges, define solutions and deliver outcomes with minimal supervision while collaborating closely with security, engineering and operational teams.

What You'll Be Doing

Mid-Senior Security Engineer

  • Develop, test and maintain detections within Microsoft Sentinel and Defender XDR.
  • Write and optimise KQL queries to identify suspicious activity and security events.
  • Design and implement logging pipelines and onboard data sources into Sentinel.
  • Define logging requirements, collection methods and ingestion approaches.
  • Analyse telemetry to identify gaps in data quality, coverage and detection capability.
  • Tune detections, reduce false positives and improve monitoring effectiveness.
  • Translate threat intelligence into practical detection use cases.
  • Work with SOC, Threat Hunting and Incident Response teams to improve outcomes.
  • Use PowerShell or Python to automate processes and improve efficiency.
  • Independently manage and deliver assigned workstreams.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Senior Security Engineer

In addition to the above:

  • Lead the onboarding and integration of complex environments into the wider security architecture.
  • Design target-state logging, monitoring and detection architectures.
  • Produce Low-Level Designs (LLDs) and technical documentation.
  • Lead migrations from platforms such as Splunk and CrowdStrike to Microsoft Sentinel and Defender.
  • Design centralised and multi-tenant logging solutions across Microsoft and AWS environments.
  • Establish logging and security foundations where capabilities are immature or inconsistent.
  • Drive improvements in detection maturity, monitoring coverage and security posture.
  • Provide technical leadership, mentoring and architectural guidance.
  • Operate with significant autonomy, making key technical decisions and driving delivery across complex environments.

What You'll Bring

Mid-Senior Security Engineer

  • Experience in Security Engineering, Detection Engineering, SOC Engineering or a similar cyber security role.
  • Hands-on experience with Microsoft Sentinel, Defender XDR and Intune.
  • Strong understanding of SIEM, logging architecture, detection engineering and endpoint security.
  • Experience with KQL and PowerShell and/or Python.
  • Knowledge of MITRE ATT&CK and security monitoring best practices.
  • Experience onboarding data sources, tuning detections and improving detection coverage.
  • Ability to work independently, take ownership of deliverables and solve problems proactively.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Senior Security Engineer

In addition to the above:

  • Extensive experience designing and implementing enterprise-scale security monitoring and detection capabilities.
  • Deep expertise in Microsoft Sentinel, Defender XDR and advanced KQL.
  • Experience designing logging architectures and producing technical designs/LLDs.
  • Proven experience leading security platform migrations and transformation programmes.
  • Strong understanding of Azure, AWS and multi-environment security architectures.
  • Ability to independently define architectural direction, make technical decisions and lead complex initiatives.
  • Experience mentoring engineers and engaging with stakeholders at all levels.

Key Technologies

Microsoft Sentinel • Microsoft Defender XDR • Defender for Endpoint • Intune • Azure Log Analytics • KQL • PowerShell • Python • Cribl (desirable) • Splunk • CrowdStrike • AWS • MITRE ATT&CK

Why join?

NETbuilder's history is deeply rooted in the digital landscape, meaning we bring decades of experience and unrivalled expertise to every project we work on. You will join a world-class team of experienced consultants and be given the full support, resources, and backing to build something genuinely new within the NETbuilder group.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this