Security Engineer - SIEM/XDR - London
NewBe an early applicantSalary: £70,000 - 70,000 per year
Requirements:- Strong Security Engineer, security engineering, or detection engineering experience
- Hands-on SIEM and XDR tooling experience, ideally Microsoft Sentinel and Microsoft Defender for Endpoint
- Experience with detection engineering, detection-as-code, KQL, security content, and alert logic
- Experience with security telemetry, logging pipelines, data quality, and improving telemetry coverage
- Experience in cloud security engineering and scalable security architecture design
- Experience with automation, SOAR, playbooks, enrichment workflows, and response improvement
- Scripting or programming skills such as Python and PowerShell
- Experience with infrastructure-as-code, CI/CD pipelines, version control, and documentation standards
- Experience integrating APIs, security tooling, and onboarding new data sources
- Knowledge of Windows and Linux operating systems
- Ability to own engineering backlog, priorities, and delivery across detection and platform improvements
- UK-based and able to travel to UK sites at short notice
- Design, build, and maintain scalable security detection and response capabilities across SIEM, XDR, cloud, and endpoint platforms
- Set engineering direction, standards, and quality across detection, telemetry, and automation
- Focus on detection-as-code, telemetry optimisation, and automated response workflows
- Work closely with SOC leadership and engineering teams to improve detection effectiveness
- Integrate new data sources and enhance logging quality
- Build automation and support scalable cloud security outcomes
- Azure
- CI/CD
- Cloud
- Support
- Linux
- PowerShell
- Python
- Security
- Windows
- API
More:
We are a leading tech company offering a permanent Security Engineer (SIEM / XDR) opportunity in our London office on a hybrid basis, with attendance typically 1-2 times a month. We offer a great package and strong career progression, and the role sits within a collaborative environment working closely with SOC leadership and engineering teams to improve detection, telemetry, automation, and cloud security outcomes. Desirable experience includes InfoSec, Microsoft, or Azure certifications.
last updated 35 week of 2026