SOC Engineer Detection
Sopra Steria · Farnborough · posted 17 days ago
Going rate £48,500UK median £54,647
Home Office going rates from
Occupation
2135Cyber security professionals
Going rate for this occupation: £48,500 · UK median pay £54,647
Home Office going rates from
Where this salary sits
- UK pay for this occupation
- This role£60,000 to £65,000stated
- Going rate£48,500
- UK median£54,647
View these figures as a table
| Percentile | Pay |
|---|---|
| 10th | £32,471 |
| 25th | £42,761 |
| 50th | £54,647 |
| 75th | £71,808 |
| Going rate | £48,500 |
| UK median | £54,647 |
Sponsorship
Sponsorship chance
Very high
- Licensed for Skilled Worker
- Occupation is eligible for Skilled Worker
- Salary clears the going rate
On the public records we hold, sponsorship for this role looks likely: licensed for Skilled Worker, and occupation is eligible for Skilled Worker.
Sign in to see how you fit and draft a cover letter
We read this advert for what it asks, check each line against your CV and show you the evidence for every judgement.
Sign inFull advert
Shape the Future of Microsoft Sentinel Detection Engineering.
Are you passionate about Microsoft Sentinel, KQL and building high-quality detections that help a SOC identify threats effectively?
We're looking for a Senior Detection Engineer to join our growing Aerospace, Defence & Security business. You'll play a key role in designing, developing, testing and improving detection content in Microsoft Sentinel, translating threat behaviours and security requirements into reliable analytics.
This is an opportunity to join the Detection Engineering team and help strengthen detection coverage, reduce false positives and ensure detection content remains accurate, performant and operationally useful.
As a Senior Detection Engineer, you'll own detection use cases through their lifecycle, from research and data validation through KQL development, testing, deployment, tuning and continuous improvement.
Hybrid: Farnborough 3 days per week, 2 days home based.
SC Cleared or eligible.
What You'll Be Doing:
Design, develop and maintain Microsoft Sentinel analytics rules using KQL. Translate threat intelligence, attacker behaviours and operational requirements into measurable detection use cases. Map detection content to the MITRE ATT&CK framework and help identify gaps in detection coverage. Validate required log sources, schemas and field mappings before developing detection logic. Test detections against representative data and document expected results, limitations and test evidence. Tune analytics to reduce false positives while preserving detection fidelity and query performance. Manage detection content through peer review, controlled deployment, versioning and ongoing lifecycle maintenance. Work with SOC analysts, threat intelligence and platform engineers to improve detections using operational feedback. Support threat hunting, retrospective searches and investigations using Microsoft Sentinel and KQL. Contribute to detection engineering standards, governance, coverage reporting and continuous improvement.
What you will bring:
Strong hands-on experience with Microsoft Sentinel in a detection engineering or security engineering role. Advanced KQL skills, including building, troubleshooting and optimising queries across multiple data sources. Experience creating, testing, deploying and tuning scheduled analytics rules and other Sentinel detection content. A good understanding of detection engineering principles, false-positive reduction and the detection content lifecycle. Experience developing threat-informed use cases and mapping detections to MITRE ATT&CK tactics and techniques. Ability to assess log source suitability, data quality, parsing and field availability for detection requirements. Experience with Git-based version control, peer review and controlled deployment of detection content. Strong analytical, troubleshooting and documentation skills, with the ability to explain detection logic clearly. A collaborative approach to working with SOC analysts, threat intelligence, platform engineers and other security teams.
Information from public records, not immigration advice.