Microsoft Sentinel Detection Engineer (Contract) at Cloud People, London Area, £500-£550 per day

£500 - £550 per day

Contract Description

Microsoft Sentinel Detection Engineer

💰 £500 to £550 per day DOE, outside IR35

📍 Hybrid, London two days per week


Company & role

A specialist Microsoft security partner with its own managed detection and response service is bringing in contract engineers to support a large enterprise security programme. It is an initial contract running roughly November to March, with starts targeted within around three weeks.

This role owns the SIEM, both the platform and the content running on it. You will be the Microsoft Sentinel and detection engineering expert, improving telemetry, building high fidelity detections and automating the monitoring capability for a proactive security function. You will work closely with Security Operations, Infrastructure, Cloud and Application teams.


Why This Role Stands Out

  • Proper detection engineering. Detection as Code, CI/CD and peer review, not just tuning someone else's rules.
  • Ownership of both platform and content, so you shape how the whole monitoring capability works.
  • Meaty telemetry work, from Data Collection Rules and custom parsers through to API integrations and ingestion optimisation.
  • Outside IR35 with a defined initial term, and a team that wants to move fast.


Key Responsibilities

  • Act as the subject matter expert for Microsoft Sentinel, detection engineering and security monitoring architecture
  • Design, test, deploy and tune analytics rules, correlation logic and hunting queries aligned to MITRE ATT&CK
  • Engineer data connectors, ingestion pipelines, Data Collection Rules, custom parsers, custom tables and API integrations
  • Set logging standards, onboarding patterns and governance across the detection engineering lifecycle
  • Build automation with Logic Apps, Azure Functions, REST APIs, PowerShell and Python
  • Integrate endpoint, identity, cloud, network and infrastructure controls with Sentinel and the Defender ecosystem
  • Build workbooks, dashboards, platform health monitoring and KPI reporting
  • Produce high and low level designs and engineering standards, and lead upgrades, migrations and proof of concepts, including planned out of hours support for major changes


Ideal Experience

  • Proven SIEM, detection or security platform engineering in a large enterprise environment
  • Advanced Microsoft Sentinel, covering architecture, KQL, analytics rules, hunting, workbooks, watchlists and playbooks
  • Strong Defender XDR across Endpoint, Identity and Cloud
  • Telemetry onboarding with Azure Monitor Agent, Azure Arc, Data Collection Rules, Log Analytics and custom ingestion
  • Windows Event Forwarding, XPath filtering, Sysmon and PowerShell logging
  • Detection as Code using Azure DevOps or Git based CI/CD, Infrastructure as Code concepts and ideally tools such as Cribl
  • Automation with PowerShell, Python and REST APIs
  • SC 200 or AZ 500 desirable


If you are the person who builds the detections other analysts rely on and you enjoy making a SIEM genuinely better, this is one to look at.