Job Search and Career Advice Platform

Enable job alerts via email!

Senior Microsoft Security Engineer

SecurityHQ

City of London

On-site

GBP 70,000 - 90,000

Full time

30+ days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A global cybersecurity company is seeking a Senior Microsoft Security Engineer to oversee the Microsoft security stack and manage SIEM & SOAR solutions. The successful candidate will have over 5 years of experience with Microsoft technologies and a strong technical background in security. This role offers a hybrid working environment in London and the opportunity to mentor team members while engaging directly with clients.

Qualifications

  • 5+ years experience with Azure, Microsoft Sentinel, and Defender XDR products.
  • 4+ years in customer-facing consulting roles.
  • 2+ years technical background in Security, SIEMs, Networking, or Datacentre Technology.
  • Strong knowledge of distributed computing, microservices, and security architecture.
  • Proficiency with SIEM/SOAR, XDR, Purview DLP, and infrastructure as code.
  • Excellent communication skills in English, both written and verbal.
  • At least one of: Az500, SC100, SC401 Level Certification.

Responsibilities

  • Configure and maintain Microsoft Sentinel, including data onboarding and automation.
  • Develop dashboards and reporting pipelines for incident trends.
  • Manage the Microsoft Defender XDR suite and policy configuration.
  • Implement Microsoft Purview for data governance and compliance.
  • Architect scalable, secure solutions for clients.
  • Mentor team members and foster collaboration.

Skills

Azure
Microsoft Sentinel
Defender XDR
KQL
PowerShell
Automation
Security Architecture

Education

Bachelor’s degree or equivalent

Tools

Microsoft Sentinel
Datadog
QRadar
Job description
Job Description

We are seeking a Senior Microsoft Security Engineer with advanced expertise in the Microsoft security stack. You will play a key role in developing, deploying, and managing SIEM & SOAR solutions, and will be instrumental in safeguarding our clients’ digital environments. This position is based at our London office in Canary Wharf and follows a hybrid working pattern of two to three days per week on-site. The role involves some travel and reports directly to the Chief Technology Officer.

Responsibilities
  • Configure and maintain Microsoft Sentinel (SIEM/SOAR), including data onboarding, custom log parsing, and automation using Logic Apps.
  • Develop dashboards and reporting pipelines for incident trends and rule performance.
  • Manage the Microsoft Defender XDR suite (Endpoint, Identity, Office 365, Cloud Apps, Cloud), including policy configuration, alert tuning, and integration.
  • Implement Microsoft Purview for data governance, DLP, insider risk, and compliance monitoring.
  • Architect and implement scalable, secure solutions for clients, directly engaging with stakeholders to understand requirements.
  • Mentor team members and foster a culture of collaboration and continuous improvement.
  • Participate in a shared on-call support model and occasional travel as required.
About SHQ

SecurityHQ is a global cybersecurity company. Our specialist teams design, engineer and manage solutions that do three things: Promote clarity and trust in a complex world. Build momentum around improving security posture. And increase the value of cybersecurity investment within organizations. Free from limitations, and inclusive of all requirements, we focus on defending today, while mitigating the risks of tomorrow. And into the future. Our solutions are tailored to our customers and their unique context. Around the clock, 365 days per year, our customers are never alone. SecurityHQ – We’re focused on engineering cybersecurity, by design.

Qualifications
  • 5+ years experience with Azure, Microsoft Sentinel, and Defender XDR products.
  • 4+ years in customer-facing consulting roles.
  • 2+ years technical background in Security, SIEMs, Networking, or Datacentre Technology.
  • Strong knowledge of distributed computing, microservices, and security architecture.
  • Proficiency with SIEM/SOAR (Microsoft Sentinel, KQL, Logic Apps), XDR, Purview DLP, automation (PowerShell, Azure CLI, Graph API), and infrastructure as code (ARM, Bicep, Terraform).
  • Familiarity with cloud/identity security (Azure AD/Entra ID, Conditional Access), threat frameworks (MITRE ATT&CK, NIST, CIS), and documentation best practices.
  • Excellent communication skills in English, both written and verbal.
  • Bachelor’s degree or equivalent from an accredited institution.
  • At least one of: Az500, SC100, SC401 Level Certification (AWS certifications a plus).
  • Experience with Datadog or QRadar is advantageous.

Job Reference Number: UK004

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.