London (Hybrid)
6-month FTC
We’re hiring for an experienced Detection Engineer to join our Security and Observability practice, working across a range of global client environments.
You’ll be responsible for developing and enhancing detection capabilities across modern Microsoft security platforms, using Microsoft Sentinel, Defender XDR and KQL to develop, test and optimise effective detection logic.
The role combines hands-on engineering with problem-solving and collaboration. You’ll work with security teams to identify gaps, investigate detection challenges, improve existing use cases and develop new capabilities in response to changing threats and operational requirements.
If you enjoy getting into the detail of security data, writing detection logic and continuously finding ways to make detection capabilities more effective, we’d like to hear from you.
What you’ll be doing:
- Develop, test and maintain detection rules across Microsoft Sentinel and Defender XDR.
- Write and optimise KQL queries to identify suspicious activity and security events.
- Analyse telemetry and investigate gaps in data quality, coverage and detection capability.
- Translate threat intelligence and security requirements into practical detection use cases.
- Work with SOC, Threat Hunting and Incident Response teams to improve detection outcomes.
- Use PowerShell or Python to automate repetitive tasks and enhance detection workflows.
- Contribute to the ongoing development of detection engineering standards and best practices.
What you’ll bring:
- 4+ years' experience in Detection Engineering, Security Engineering, SOC Engineering, Threat Detection or a related cybersecurity role
- Hands-on experience creating, developing and tuning detections in Microsoft Sentinel and Microsoft Defender XDR
- Strong hands-on experience writing and optimising KQL queries
- Strong understanding of log pipelines, schema mapping and telemetry quality, including ASIM
- Experience tuning detections, reducing false positives and improving detection coverage
- Scripting experience with PowerShell or Python
- Good understanding of threat detection methodologies, including MITRE ATT&CK
- Ability to work collaboratively across cyber security, technology and operational teams
- Experience working in a client-facing, consulting or managed services environment would be advantageous
Why join NETbuilder?
Ourhistory is deeply rooted in the digital landscape, meaning we bring decades of experience and unrivalled expertise to every project we work on. You will join a world-class team of experienced consultants and be given the full support, resources, and backing to build something genuinely new within the NETbuilder group.
Pay: From £70,000.00 per year
Work Location: Hybrid remote in London