SIEM Content & Platform Engineer - London (Remote/Hybrid) - Outside IR35 Contract
We are supporting an exciting client who is looking for an experienced SIEM Content & Platform Engineer to join their Cyber Security team on a contract basis. This role will focus on security monitoring, detection engineering, platform optimisation, automation, and improving enterprise cyber resilience.
Requirements:
- Strong hands-on experience with Microsoft Sentinel and Microsoft Defender XDR in large enterprise environments.
- Experience developing and tuning analytics rules, threat hunting queries, correlation logic and detection content aligned to security frameworks such as MITRE ATT&CK.
- Proven experience onboarding and optimising cloud, infrastructure, application and security telemetry within a SIEM platform.
- Strong automation skills using Logic Apps, Azure Functions, PowerShell, Python and REST APIs.
- Experience with security engineering, platform hardening, vulnerability remediation, technical risk assessment and operational support.
Desirable:
- Experience with Azure DevOps, CI/CD, Detection-as-Code, and Infrastructure-as-Code.
- Microsoft certifications such as SC-200 or AZ-500.
We're looking for a contractor who can act as a subject matter expert across SIEM engineering, detection content development and security monitoring architecture, with a strong background in Microsoft Sentinel, Detection Engineering, Security Automation and Cyber Security Operations.
SIEM Content & Platform Engineer - London (Remote/Hybrid) - Outside IR35 Contract