Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
CyberOne

SIEM Content Engineer

CyberOne

. Act as a Subject Matter Expert for Microsoft Sentinel, detection engineering, security monitoring architecture, and associated security platforms .

Posted 10/2/2026full-timeLondon • United KingdomMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Microsoft Sentinel and security platform engineering, with a strong focus on detection engineering, automation, and security architecture. Proficient in developing high-fidelity detections, threat-hunting queries, and integrating security controls across various environments.

Highest-signal resume keywords
Microsoft Sentinel AdministrationDetection EngineeringSecurity ArchitectureAutomation with PowerShell and PythonSIEM Integration

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Detection EngineeringSecurity Monitoring ArchitectureHigh-Fidelity DetectionsThreat-Hunting QueriesData Collection RulesVulnerability RemediationTechnical Risk AssessmentKQLMITRE ATT&CK MappingCross-Data Correlation
Tools & Technologies
Microsoft Defender XDRLogic AppsAzure FunctionsREST APIsAzure Monitor AgentLog AnalyticsWindows Event ForwardingSysmonAzure DevOpsCribl
Certifications & Qualifications
Microsoft SC-200Microsoft AZ-500
Industry Keywords
Security EngineeringCloud SecurityInfrastructure SecurityTelemetryDetection-as-Code

Tech Stack

Tools & technologies
AzureCloudCyber SecurityPython

About the role

Key responsibilities & impact
  • Act as a Subject Matter Expert for Microsoft Sentinel, detection engineering, security monitoring architecture, and associated security platforms
  • Design, develop, test, deploy, and tune analytics rules, correlation logic, threat-hunting queries, and reusable detection content aligned with MITRE ATT&CK
  • Engineer and optimise data connectors, ingestion pipelines, Data Collection Rules, custom parsers, custom tables, and API-based integrations
  • Develop logging standards, onboarding patterns, use-case documentation, and governance for the detection engineering lifecycle
  • Design and implement automation using Logic Apps, Azure Functions, REST APIs, PowerShell, and Python
  • Perform security engineering activities including secure solution design, technical risk assessment, platform hardening, vulnerability remediation, and security control validation
  • Support integration and engineering of endpoint, identity, cloud, network, and infrastructure security controls with the SIEM and Defender ecosystem
  • Build Sentinel Workbooks, dashboards, platform health monitoring, and KPI/KRI reporting for the Proactive Security function
  • Produce and maintain High-Level Designs, Low-Level Designs, engineering standards, operating procedures, and support documentation
  • Lead platform enhancements, proof-of-concepts, migrations, upgrades, troubleshooting, and technical support during critical incidents and major changes
  • Collaborate with Security Operations, Infrastructure, Cloud, and Application teams to deliver scalable telemetry, high-fidelity detections, secure integrations, and continuous improvement of proactive security monitoring

Requirements

What you’ll need
  • Proven experience in SIEM, detection, or security platform engineering within a large enterprise environment
  • Strong hands-on experience with Microsoft Sentinel and Microsoft Defender XDR, including Endpoint, Identity, and Cloud
  • Experience developing and tuning high-fidelity detections, threat-hunting queries, cross-data correlation, and contextual enrichment
  • Experience onboarding infrastructure, cloud, application, and security telemetry into a SIEM
  • Practical experience with security architecture, platform hardening, vulnerability remediation, technical risk assessment, and security control validation
  • Experience with REST APIs, PowerShell, Python, automation, enterprise troubleshooting, and operational support
  • Experience applying Detection-as-Code, CI/CD, source control, and peer-review practices
  • Advanced Microsoft Sentinel administration, architecture, KQL, analytics rules, hunting, workbooks, watchlists, playbooks, and optimisation
  • Knowledge of Azure Monitor Agent, Azure Arc, Data Collection Rules, Log Analytics, custom tables, parsers, and custom ingestion
  • Knowledge of Windows Event Forwarding and Collection, XPath filtering, Windows Event IDs, Sysmon, and PowerShell logging
  • Knowledge of Azure Functions, Logic Apps, REST APIs, PowerShell, Python, and security workflow automation
  • Knowledge of MITRE ATT&CK mapping, threat-informed defence, detection coverage analysis, and use-case lifecycle management
  • Security engineering knowledge across endpoint, identity, cloud, network, and hybrid infrastructure controls
  • Knowledge of Azure DevOps or equivalent Git-based CI/CD, Infrastructure-as-Code concepts, secure development practices, and tools such as Cribl
  • Degree or equivalent professional experience in Information Technology, Cyber Security, Engineering, or a related discipline
  • Willingness to provide planned out-of-hours support for critical upgrades and major changes when required
  • Microsoft SC-200 or AZ-500 certifications are desirable
  • Additional cloud, SIEM, security engineering, or automation certifications are advantageous

Benefits

Comp & perks
  • Competitive compensation
  • Career growth opportunities
  • Access to continuous learning and certifications
  • Work with cutting-edge Azure technologies
  • Opportunity to work on impactful cloud initiatives across various industries
  • Access to cutting-edge MXDR platform and proprietary SecOps tools
  • Rapid growth and fast-track leadership opportunities
  • Culture of open feedback and innovation