Senior SOC Engineer

United Kingdom
Today
Seniority
Senior
Posted
23 Aug 2026 (Today)

Senior SecOps Engineer - Microsoft Security

UK | Predominantly Remote | Occasional presence in London

Permanent

We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team.

This is not a traditional SOC Analyst position.

We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments.

The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments.

The Role

Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions.

Responsibilities will include:

Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR

Engineering and optimisation of SIEM capabilities across enterprise environments

Developing and tuning KQL queries, analytics and detection rules

Designing and implementing SOC automation, playbooks and scripting

Improving security event detection and response capabilities

Conducting Microsoft tenant health checks, security audits and architecture reviews

Analysing cloud security risks and recommending appropriate security controls

Supporting complex incident triage and resolution

Designing and documenting security engineering standards and processes

Researching and implementing new Microsoft security capabilities

Producing high-quality technical and customer-facing documentation

Working directly with customers and technical stakeholders

Supporting and mentoring more junior members of the engineering team

Essential Experience

To be considered, you should have strong commercial experience across the following:

Microsoft Sentinel / Azure Sentinel

Microsoft Defender / Defender XDR

Strong KQL / Kusto Query Language capability

Security Engineering, SOC Engineering or Microsoft Security Consulting

SIEM engineering rather than solely alert monitoring or incident triage

Detection engineering and security monitoring optimisation

Automation, scripting, SOAR or Sentinel playbooks

Cloud security assessments, controls and risk analysis

Designing and documenting security processes

Customer-facing technical deliveryCandidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position.

Highly Desirable

Experience across any of the following would be particularly valuable:

Microsoft Purview

Microsoft Defender for Endpoint

Defender for Cloud

Defender for Identity

Defender for Office 365

Microsoft Entra ID

Intune

Azure security architecture

Logic Apps / Sentinel playbooks

PowerShell or Python

MITRE ATT&CK

Microsoft Security architecture and tenant assessmentsPrevious experience working directly for Microsoft, or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous.

Microsoft Certifications

Relevant Microsoft certifications are strongly preferred, particularly:

SC-200 - Microsoft Security Operations Analyst

AZ-500 - Azure Security Engineer Associate

AZ-104 - Azure Administrator Associate

AZ-305 - Azure Solutions Architect ExpertEquivalent or additional Microsoft Security certifications will also be considered.

The Opportunity

This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function.

You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development.

The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities.

If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering, email your CV

If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website

Related Jobs

View all jobs

Senior SOC Engineer

Fazer Recruitment Cardiff, Cymru / Wales, CF10 2AF, United Kingdom
£65,000 – £70,000 pa

SOC Engineer

4Square Recruitment Ltd Cambridge, United Kingdom
£40,000 – £80,000 pa

Cyber Security Lead

Rebel Recruitment Nottinghamshire, United Kingdom
£65,000 – £70,000 pa Hybrid

Senior SOC Analyst

Ballantyne Technology Associates Ltd Reading, Berkshire, United Kingdom
£75,000 – £90,000 pa Hybrid

Senior SOC Analyst

Ballantyne Technology Associates Ltd Reading, Berkshire

Senior Detection Engineer (Consultancy)

Fazer Recruitment Reading, United Kingdom
£85,000 – £90,000 pa

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.