NETbuilder
Senior Security Engineer - Microsoft Sentinel & Defender XDR

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Senior Security Engineer
London (Hybrid)
Salary dependent on experience
We are looking for a Senior Security Engineer to design, build, and mature security monitoring, logging, and detection across Microsoft security platforms. You will work with Microsoft Sentinel, Microsoft Defender XDR, KQL, and automation tooling to improve detection coverage, onboard data sources, and strengthen enterprise security monitoring.
This is a role for someone who works with real autonomy. You will identify the problems, define the solutions, and deliver the outcomes, working closely with security, engineering, and operations teams.
What You Will Do
- Lead the onboarding and integration of complex environments into the wider security architecture.
- Design target-state logging, monitoring, and detection architectures, and produce Low-Level Designs (LLDs) and technical documentation.
- Lead migrations from platforms such as Splunk and CrowdStrike to Microsoft Sentinel and Defender.
- Design centralized and multi-tenant logging solutions across Microsoft and AWS environments.
- Establish logging and security foundations where existing capability is immature or inconsistent.
- Build, test, and maintain detections in Microsoft Sentinel and Defender XDR, writing and optimizing KQL to surface suspicious activity.
- Define logging requirements, collection methods, and ingestion approaches, and build the pipelines that bring data sources into Sentinel.
- Analyze telemetry to find gaps in data quality, coverage, and detection capability.
- Tune detections to cut false positives and improve monitoring effectiveness.
- Turn threat intelligence into practical detection use cases.
- Work with SOC, Threat Hunting, and Incident Response teams to improve outcomes.
- Automate processes with PowerShell or Python.
- Provide technical leadership, mentoring, and architectural guidance to other engineers.
- Make key technical decisions and drive delivery across complex environments.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What You Will Bring
- Extensive experience designing and implementing enterprise-scale security monitoring and detection in a Security Engineering, Detection Engineering, or SOC Engineering role.
- Deep expertise in Microsoft Sentinel, Defender XDR, and advanced KQL, plus hands-on experience with Intune.
- Strong grasp of SIEM, logging architecture, detection engineering, and endpoint security.
- Experience designing logging architectures and producing technical designs and LLDs.
- A track record of leading security platform migrations and transformation programs.
- Strong understanding of Azure, AWS, and multi-environment security architectures.
- Working knowledge of MITRE ATT&CK and security monitoring best practice.
- Scripting experience in PowerShell and/or Python.
- The ability to set architectural direction, make technical decisions, and lead complex initiatives independently.
- Experience mentoring engineers and working with stakeholders at all levels.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Key Technologies
- Microsoft Sentinel
- Microsoft Defender XDR
- Defender for Endpoint
- Intune
- Azure Log Analytics
- KQL
- PowerShell
- Python
- Cribl (desirable)
- Splunk
- CrowdStrike
- AWS
- MITRE ATT&CK
Why Join NETbuilder?
NETbuilder has been a specialist technology partner since 1999. You will join a team of experienced security consultants and have the support, resources, and backing to build a genuinely new capability.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location