Role Overview
We are looking for a Security Content Engineer to join a fully remote, UK-based role within a Threat Fusion Cell, focused on building automated security analysis solutions for a global client base.
The role centres on developing, tuning, and maintaining high-fidelity detection and automation content across Microsoft Sentinel, requiring UK citizenship and 5-8 years of detection engineering or security operations experience.
Key Responsibilities
- Autonomously develop, test, and maintain high-fidelity detection logic in KQL for Microsoft Sentinel, owning a portfolio of content and ensuring its long-term effectiveness and performance
- Conduct advanced global tuning and optimisation to improve SOC efficiency, proactively identifying and resolving sources of alert fatigue and false positives across the customer base
- Independently research emerging threats, attack vectors, and high-risk vulnerabilities to design proactive detection strategies aligned to MITRE ATT&CK
- Design and build scalable automation content for security workflows including product onboarding and incident enrichment, with a focus on reusability using SOAR platforms, Logic Apps, APIs, and scripting
- Act as a technical resource for clients on complex tuning requests, collaborate with integration teams on log ingestion optimisation, and contribute to the evolution of security policies and automation frameworks
Skills Required
- 5-8 years of detection engineering, security operations, or content creation experience with deep hands-on expertise across Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps
- High proficiency in KQL - proven experience writing complex, optimised queries for detection, tuning, and threat hunting at scale
- Strong experience automating security workflows using SOAR platforms, APIs, Python, or PowerShell, with the ability to build scalable and reusable automation content
- In-depth knowledge of attacker TTPs, the MITRE ATT&CK framework, and modern blue team operations, with strong analytical skills across log analysis and digital forensics
- Proven ability to operate autonomously across complex, competing priorities - desirable: MDR environment experience, detections-as-code via CI/CD and Git, and certifications such as GCIH, GDAT, GCFA, or OSCP. UK citizenship required