Role: Sentinel Engineer
Type: Contract (Inside IR35)
Duration: 6 months
Location: Remote
Overview We are seeking an experienced
Microsoft Sentinel Engineer with a strong cyber security background to support the delivery, optimisation, and ongoing development of a large-scale Microsoft security environment. The successful candidate will play a key role in enhancing security monitoring, threat detection, automation, and SIEM capabilities, whilst helping drive security improvements across cloud and hybrid platforms.
This role is ideally suited to a hands-on Security Engineer with proven experience implementing and managing Microsoft Sentinel, delivering SIEM migrations, and working across the wider Microsoft Security stack. You will work closely with Security Operations, Infrastructure, and Cloud teams to strengthen the organisation's security posture and improve incident detection and response capabilities.
Key Responsibilities- Design, implement, configure and support Microsoft Sentinel solutions.
- Lead and support SIEM migration projects from legacy platforms into Microsoft Sentinel.
- Develop and maintain analytics rules, alerting capabilities and detection use cases.
- Create and optimise Kusto Query Language (KQL) queries for threat hunting, incident investigation and reporting.
- Integrate and onboard new log sources and security tooling into Sentinel.
- Configure and support Azure Monitor and Log Analytics environments.
- Develop automation and orchestration playbooks using Azure Logic Apps.
- Work with Microsoft Defender technologies to improve threat detection and response.
- Build dashboards, workbooks and reporting capabilities for operational and management teams.
- Support Security Operations teams with incident response, threat hunting and security investigations.
- Tune detections and reduce false positives whilst improving overall visibility and coverage.
- Implement security best practices aligned to industry frameworks and standards.
- Collaborate with internal and third-party stakeholders across security, infrastructure and cloud teams.
Essential Skills & Experience Technical Skills- Microsoft Sentinel
- SIEM Migration Experience
- Log Analytics
- Azure Monitor
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Cloud
- Microsoft 365 Security
- Kusto Query Language (KQL)
- Azure Logic Apps
- Azure Lighthouse
Experience- Minimum 5 years' experience within Cyber Security, Security Engineering, SOC, SIEM Engineering or related disciplines.
- Strong understanding of SIEM, SOAR, threat detection and incident response.
- Demonstrable experience designing and implementing Microsoft Sentinel solutions.
- Experience developing detection rules, use cases and security monitoring capabilities.
- Strong threat hunting and security investigation experience.
- Knowledge of MITRE ATT&CK and modern security operations practices.
- Experience working within enterprise-scale Azure and Microsoft security environments.
Desirable Skills- QRadar
- Devo
- SentinelOne
- Mimecast
- Check Point
- Qualys
- Azure Networking
- Terraform
- PowerShell
- Python
- GitHub
- Azure DevOps
- ServiceNow
- Azure RBAC
- Azure Monitor Agent (AMA)
- Data Collection Rules (DCR)
- Syslog
- CEF
- Windows Event Logging
- Linux Logging
- REST APIs
Candidate Profile The ideal candidate will be a proactive and technically strong Security Engineer who combines deep Microsoft Sentinel expertise with a broad understanding of cyber security operations. You will be comfortable working in a fast-paced environment, engaging with stakeholders at all levels, and driving improvements across monitoring, detection, automation and incident response capabilities.