Назад
Company hidden
2 дня назад

Security Monitoring & Detection Engineering Lead (Microsoft Sentinel)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Monitoring & Detection Engineering Lead (Microsoft Sentinel): Leading the architecture, engineering and operational performance of security monitoring, detection and incident response across enterprise, Azure and AWS environments with an accent on Microsoft Sentinel, KQL, telemetry architecture and threat-informed defence. Focus on designing detection content and automated response workflows, leading complex cyber investigations, and improving monitoring effectiveness across the internal team and MSSP.

Location: Hybrid, with at least 50% of working time in the Manchester or London office; the first 3 months are full-time in the office.

Company

hirify.global is a UK investment platform business providing ISA, pension and dealing account solutions to more than 723,000 customers.

What you will do

  • Own the technical direction, roadmap and delivery performance of Security Monitoring & Detection Engineering.
  • Architect, engineer and continuously improve Microsoft Sentinel and the wider security monitoring estate.
  • Design telemetry onboarding across on-premises systems, Microsoft Azure, AWS and third-party services.
  • Lead the detection engineering lifecycle, including analytics rules, hunting queries, workbooks, testing, deployment and retirement.
  • Lead complex investigations and technical incident response, including attack reconstruction, containment and resolution.
  • Coordinate the internal team and MSSP, improve response playbooks and exercises, and report operational performance and risks.

Requirements

  • Extensive experience in security monitoring, SIEM engineering, detection engineering and incident response in complex enterprise environments.
  • Strong production experience designing, building and operating Microsoft Sentinel, with deep KQL expertise.
  • Experience engineering telemetry architectures, connectors, parsing, normalisation, retention, ingestion health, data quality and cost management.
  • Experience investigating Azure and AWS environments and integrating Microsoft Defender XDR across endpoint, identity, email and cloud security.
  • Experience building automated investigation and response workflows with Azure Logic Apps, APIs, PowerShell, Python or comparable technologies.
  • Strong communication skills and the ability to translate technical threats and capability gaps into business decisions.

Nice to have

  • Experience leading red-team, purple-team or offensive-security activities.
  • Experience in financial services or another regulated environment.
  • Relevant certifications such as BTL2, GCIH, GCIA, CRIA, CRTO, OSCP, OSWP or CEH.

Culture & Benefits

  • 27 days of holiday, increasing with service, plus bank holidays and a buy/sell scheme.
  • 8% pension with matched contributions, discretionary bonus and share schemes.
  • Private healthcare, dental plan, healthcare cash plan and enhanced family leave.
  • Learning and development opportunities, social events and a supportive team environment.
  • Travel and bike loan schemes and an Employee Assistance Programme.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →