Experis UK
Senior SOC Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Senior SecOps Engineer - Microsoft Security
UK | Predominantly Remote | Occasional presence in London
Permanent
We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team.
This is not a traditional SOC Analyst position.
We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments.
The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments.
The Role
Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions.
Responsibilities Will Include
- Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR
- Engineering and optimisation of SIEM capabilities across enterprise environments
- Developing and tuning KQL queries, analytics and detection rules
- Designing and implementing SOC automation, playbooks and scripting
- Improving security event detection and response capabilities
- Conducting Microsoft tenant health checks, security audits and architecture reviews
- Analysing cloud security risks and recommending appropriate security controls
- Supporting complex incident triage and resolution
- Designing and documenting security engineering standards and processes
- Researching and implementing new Microsoft security capabilities
- Producing high-quality technical and customer-facing documentation
- Working directly with customers and technical stakeholders
- Supporting and mentoring more junior members of the engineering team
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Experience
To be considered, you should have strong commercial experience across the following:
- Microsoft Sentinel / Azure Sentinel
- Microsoft Defender / Defender XDR
- Strong KQL / Kusto Query Language capability
- Security Engineering, SOC Engineering or Microsoft Security Consulting
- SIEM engineering rather than solely alert monitoring or incident triage
- Detection engineering and security monitoring optimisation
- Automation, scripting, SOAR or Sentinel playbooks
- Cloud security assessments, controls and risk analysis
- Designing and documenting security processes
- Customer-facing technical delivery
Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position.
Highly Desirable
Experience across any of the following would be particularly valuable:
- Microsoft Purview
- Microsoft Defender for Endpoint
- Defender for Cloud
- Defender for Identity
- Defender for Office 365
- Microsoft Entra ID
- Intune
- Azure security architecture
- Logic Apps / Sentinel playbooks
- PowerShell or Python
- MITRE ATT&CK
- Microsoft Security architecture and tenant assessments


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Previous experience working directly for Microsoft, or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous.
Microsoft Certifications
Relevant Microsoft Certifications Are Strongly Preferred, Particularly
- SC-200 - Microsoft Security Operations Analyst
- AZ-500 - Azure Security Engineer Associate
- AZ-104 - Azure Administrator Associate
- AZ-305 - Azure Solutions Architect Expert
Equivalent or additional Microsoft Security certifications will also be considered.
The Opportunity
This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function.
You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development.
The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities.
If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering, email your CV
If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location