Netbuilder
Security Engineer - Microsoft Sentinel & Defender XDR
Job Description
Salary: £47,000 - 87,000 per year
Requirements:- Experience in Security Engineering, Detection Engineering, SOC Engineering or a similar cyber security role.
- Hands-on experience with Microsoft Sentinel, Defender XDR and Intune.
- Strong understanding of SIEM, logging architecture, detection engineering and endpoint security.
- Experience with KQL and PowerShell and/or Python.
- Knowledge of MITRE ATT&CK and security monitoring best practices.
- Experience onboarding data sources, tuning detections and improving detection coverage.
- Ability to work independently, take ownership of deliverables and solve problems proactively.
- Extensive experience designing and implementing enterprise-scale security monitoring and detection capabilities.
- Deep expertise in Microsoft Sentinel, Defender XDR and advanced KQL.
- Experience designing logging architectures and producing technical designs/LLDs.
- Proven experience leading security platform migrations and transformation programmes.
- Strong understanding of Azure, AWS and multi-environment security architectures.
- Ability to independently define architectural direction, make technical decisions and lead complex initiatives.
- Experience mentoring engineers and engaging with stakeholders at all levels.
- Ability to commute to London or plan to relocate before starting work.
- Work authorisation in the United Kingdom.
- Develop, test and maintain detections within Microsoft Sentinel and Defender XDR.
- Write and optimise KQL queries to identify suspicious activity and security events.
- Design and implement logging pipelines and onboard data sources into Sentinel.
- Define logging requirements, collection methods and ingestion approaches.
- Analyse telemetry to identify gaps in data quality, coverage and detection capability.
- Tune detections, reduce false positives and improve monitoring effectiveness.
- Translate threat intelligence into practical detection use cases.
- Work with SOC, Threat Hunting and Incident Response teams to improve outcomes.
- Use PowerShell or Python to automate processes and improve efficiency.
- Independently manage and deliver assigned workstreams.
- Lead the onboarding and integration of complex environments into the wider security architecture.
- Design target-state logging, monitoring and detection architectures.
- Produce Low-Level Designs (LLDs) and technical documentation.
- Lead migrations from platforms such as Splunk and CrowdStrike to Microsoft Sentinel and Defender.
- Design centralised and multi-tenant logging solutions across Microsoft and AWS environments.
- Establish logging and security foundations where capabilities are immature or inconsistent.
- Drive improvements in detection maturity, monitoring coverage and security posture.
- Provide technical leadership, mentoring and architectural guidance.
- Operate with significant autonomy, making key technical decisions and driving delivery across complex environments.
- AWS
- Azure
- Support
- PowerShell
- Python
- Security
- Splunk
- Cloud
More:
We are a London-based team working in a hybrid model, offering a salary dependent on experience. NETbuilder brings decades of experience and deep expertise in the digital landscape, and we are building something genuinely new within the NETbuilder group. You will join a world-class team of experienced consultants with full support, resources and backing to help shape and deliver our security monitoring and detection capabilities across Microsoft security platforms.
last updated 39 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Netbuilder
Netbuilder
London
IT
Skills & Technologies
Inferred from job description
Salary Insight
£67,000
This role
£60,000
UK median
This salary is 12% above the UK median for Software Engineers (£60,000/yr).
Based on 2024–2025 UK technology sector benchmarks