Senior Detection Engineer (Consultancy)
  • England,South East,Berkshire,Reading
  • Full Time, Permanent
  • £85,000 - £90,000 per annum, OTE, inc benefits, negotiable
Job Description:
Full job descriptionSenior Detection Engineer (Consultancy) — Remote (Southern England)
Location: Home-based across the South — client site roughly once a fortnight Salary: £70,000 + £5,000 car allowance + £15,000 bonus (£90,000 total package)
Detection engineering, done properlyThis isn’t a deployment role and it isn’t a monitoring role. You’ll spend your time on the thing most detection engineers never get enough of: designing, writing and tuning the detection logic itself.
You’ll work across customer environments as part of an established Professional Services team, alongside the SOC Engineering function. Because this is a managed security service provider, you’ll see more estates, more log sources and more genuinely different problems in a year than most in-house roles offer in five.
The split is roughly 80/20 — the large majority of your week is hands-on detection and automation work, with the remainder client-facing: workshops, coverage assessments and walking customers through what you’ve built.
Home-based, with client site visits roughly every couple of weeks. No on-call rota. No clearance requirement.
What you’ll be doing*Designing and building detection rulesets across SIEM and XDR platforms
*Writing and tuning detection logic in KQL, cutting false positives without losing coverage
*Mapping customer log sources against use cases to identify and close coverage gaps
*Designing use cases aligned to MITRE ATT&CK
*Building SOAR automations and automated response workflows
*Writing incident response playbooks for customers
*Owning the detection-as-code approach — pipelines, version control, deployment
*Running workshops, coverage assessments and use case catalogues as customer deliverables
What we’re looking for*Hands-on SIEM engineering experience, ideally Microsoft Sentinel
*Confident KQL — this is the core of the role
*SOAR playbook design in Azure Logic Apps, Cortex XSOAR or similar
*Scripting in Python or PowerShell, and comfort working with APIs
*Use case design against MITRE ATT&CK
*Working knowledge of XDR/EDR platforms and Azure telemetry sources
*Some exposure to NDR tooling such as Vectra AI or Corelight is a bonus
Consultancy or customer-facing experience is valuable, but if you’ve built strong detection engineering skills in an in-house SOC and want to move into a client-facing role, we’d still like to hear from you.
What’s on offer*£70,000 base, £5,000 car allowance and a £15,000 bonus
*Home-based across Southern England, with client visits around once a fortnight
*No on-call, no shift rota
*No security clearance required
*Roughly 80% hands-on engineering, 20% client-facing
*Technical ownership of the detection-as-code practice
*Certification and training support with a clear progression path
*Exposure to enterprise security estates across multiple industries
How to applyApply through Reed with an up-to-date CV, or get in touch for a confidential conversation.
Fazer Recruitment is acting as an employment agency in relation to this vacancy.
Job number 4050650

Increase your exposure to recruiters with ProJobs

Thousands of recruiters are looking for you in the Job Master profile database, increase your exposure 4 times with a ProJob subscription

You can cancel your subscription at any time.
metapel
Company Details:
Fazer Recruitment
Company size: 5–9 employees
Industry: Recruitment Consultancy
Fazer Recruitment is a Chester based IT Recruitment agency with over 10 years industry experience.We provide permanent and contract talent to a some o...
The jobs on site are for both men and women