Jobiglo

No results.

SIEM Content and Platform Engineer

CyberOne · London

New
Hybrid 🇬🇧 English
Microsoft Sentinel Microsoft Defender XDR Azure Functions Logic Apps REST APIs PowerShell Python KQL Azure Monitor Agent Azure Arc Data Collection Rules Log Analytics custom tables parsers Windows Event Forwarding XPath Sysmon Azure DevOps Git CI/CD Cribl

Job description

About the role

CyberOne is seeking an experienced SIEM Content & Platform Engineer to join its Cyber Security team. The role blends SIEM platform engineering, detection content development, automation and operational support to enhance enterprise monitoring and cyber resilience.

Key responsibilities

  • Act as a subject‑matter expert for Microsoft Sentinel, detection engineering and security monitoring architecture.
  • Design, develop, test, deploy and tune analytics rules, correlation logic, threat‑hunting queries and reusable detection content aligned with MITRE ATT&CK.
  • Engineer and optimise data connectors, ingestion pipelines, Data Collection Rules, custom parsers, custom tables and API‑based integrations.
  • Develop automation using Logic Apps, Azure Functions, REST APIs, PowerShell and Python.
  • Support integration of endpoint, identity, cloud, network and infrastructure security controls with the SIEM and Defender ecosystem.
  • Build Sentinel workbooks, dashboards, health monitoring and KPI/KRI reporting.
  • Produce and maintain high‑level and low‑level designs, engineering standards and support documentation.
  • Lead platform enhancements, proof‑of‑concepts, migrations, upgrades and technical support during critical incidents.

Required profile

  • Proven experience in SIEM, detection or security platform engineering within a large enterprise.
  • Strong hands‑on experience with Microsoft Sentinel and Microsoft Defender XDR (Endpoint, Identity, Cloud).
  • Experience developing high‑fidelity detections, threat‑hunting queries and cross‑data correlation.
  • Practical experience with security architecture, platform hardening, vulnerability remediation and technical risk assessment.
  • Ability to provide planned out‑of‑hours support for critical upgrades and major changes.

Required skills

  • Microsoft Sentinel administration, KQL, analytics rules, workbooks, playbooks.
  • Azure Monitor Agent, Azure Arc, Data Collection Rules, Log Analytics, custom tables, parsers.
  • Windows Event Forwarding, XPath filtering, Sysmon, PowerShell logging.
  • Automation tools: Azure Functions, Logic Apps, REST APIs, PowerShell, Python.
  • MITRE ATT&CK mapping and detection‑as‑code practices.
  • Azure DevOps or equivalent Git‑based CI/CD, Infrastructure‑as‑Code concepts.
  • Relevant Microsoft certifications (e.g., SC‑200, AZ‑500) desirable.

What we offer

  • Work with cutting‑edge Azure technologies and cloud transformation projects.
  • Dynamic team culture valuing innovation, collaboration and technical excellence.
  • Competitive compensation, career growth opportunities and continuous learning.
  • Access to proprietary MXDR platform and SecOps tools.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec CyberOne.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in the United Kingdom.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 16 hours ago

Expires 1 month from now

7 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

CyberOne

London