Cyber Security Engineer

Summary

Threat Detection Engineer role in Central London focused on Microsoft security stack—Sentinel, Defender, Entra ID, and Purview—using KQL for detection in Azure and Kubernetes environments.

Salary: £25,000 - 50,000 per year

Requirements:
  • Previously worked as a Threat Detection Engineer or in a similar role.
  • Strong expertise in KQL.
  • Hands-on experience with Microsoft Sentinel and Defender (Endpoint, Office 365).
  • Familiarity with Microsoft Entra ID, including Identity Governance.
  • Experience with Microsoft Purview, particularly DLP and data protection tools.
  • Exposure to cloud-native logging in Azure and Kubernetes environments.
  • Understanding of detection as code or everything as code approaches, including CI/CD pipelines.
  • Experience working with or alongside MSP SOC teams.
  • Awareness of Agile methodologies and ways of working.
  • Knowledge of attacker TTPs, threat modelling, and cyber security frameworks.
  • Understanding of statistics, data science, or AI/ML as applied to security.
  • Awareness of ISO 27001 standards.
  • Relevant cyber security certifications such as MS-500, AZ-500, SC-200, SC-300, SC-400, Security+, GSOC, or CCSK.
Responsibilities:
  • Design and implement threat-led detection logic informed by threat intelligence and hunting activities.
  • Develop innovative analytical techniques to identify incidents effectively.
  • Collaborate with an outsourced SOC to maintain, tune, and optimise detection catalogues.
  • Create and refine DLP, Insider Risk Management, and other security rules using cloud-native tools.
  • Monitor and ensure high-quality service delivery from external SOC providers.
  • Automate reporting on security performance and operational metrics.
  • Partner with technology teams to ensure adequate monitoring across cloud platforms, SaaS, and internal systems.
  • Document security processes, tool configurations, and contribute to service delivery documentation.
  • Support colleagues with ISO 27001 compliance and KQL-related tasks.
Technologies:
  • AI
  • Azure
  • CI/CD
  • Cloud
  • Support
  • Kubernetes
  • Office 365
  • Security
  • Network

More:

We are a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare. This is a permanent Threat Detection Engineer opportunity based in Westminster, Central London, with hybrid/remote working options and a salary of 60,000 to 80,000 plus benefits. We offer the chance to contribute to meaningful cyber security work in a modern cloud-first environment, where your expertise will directly influence how threats are detected and mitigated at scale.

last updated 35 week of 2026

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available