SIEM Content and Platform Engineer
CyberOne · London
Job description
About the role
CyberOne is seeking an experienced SIEM Content & Platform Engineer to join its Cyber Security team. The role blends SIEM platform engineering, detection content development, automation and operational support to enhance enterprise monitoring and cyber resilience.
Key responsibilities
- Act as a subject‑matter expert for Microsoft Sentinel, detection engineering and security monitoring architecture.
- Design, develop, test, deploy and tune analytics rules, correlation logic, threat‑hunting queries and reusable detection content aligned with MITRE ATT&CK.
- Engineer and optimise data connectors, ingestion pipelines, Data Collection Rules, custom parsers, custom tables and API‑based integrations.
- Develop automation using Logic Apps, Azure Functions, REST APIs, PowerShell and Python.
- Support integration of endpoint, identity, cloud, network and infrastructure security controls with the SIEM and Defender ecosystem.
- Build Sentinel workbooks, dashboards, health monitoring and KPI/KRI reporting.
- Produce and maintain high‑level and low‑level designs, engineering standards and support documentation.
- Lead platform enhancements, proof‑of‑concepts, migrations, upgrades and technical support during critical incidents.
Required profile
- Proven experience in SIEM, detection or security platform engineering within a large enterprise.
- Strong hands‑on experience with Microsoft Sentinel and Microsoft Defender XDR (Endpoint, Identity, Cloud).
- Experience developing high‑fidelity detections, threat‑hunting queries and cross‑data correlation.
- Practical experience with security architecture, platform hardening, vulnerability remediation and technical risk assessment.
- Ability to provide planned out‑of‑hours support for critical upgrades and major changes.
Required skills
- Microsoft Sentinel administration, KQL, analytics rules, workbooks, playbooks.
- Azure Monitor Agent, Azure Arc, Data Collection Rules, Log Analytics, custom tables, parsers.
- Windows Event Forwarding, XPath filtering, Sysmon, PowerShell logging.
- Automation tools: Azure Functions, Logic Apps, REST APIs, PowerShell, Python.
- MITRE ATT&CK mapping and detection‑as‑code practices.
- Azure DevOps or equivalent Git‑based CI/CD, Infrastructure‑as‑Code concepts.
- Relevant Microsoft certifications (e.g., SC‑200, AZ‑500) desirable.
What we offer
- Work with cutting‑edge Azure technologies and cloud transformation projects.
- Dynamic team culture valuing innovation, collaboration and technical excellence.
- Competitive compensation, career growth opportunities and continuous learning.
- Access to proprietary MXDR platform and SecOps tools.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United Kingdom.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 16 hours ago
Expires 1 month from now
7 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
CyberOne
London