This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
An experienced Microsoft Sentinel SME is required to support a major security transformation programme within a large enterprise environment. The successful consultant will take ownership of the Microsoft Sentinel platform, helping to improve detection capabilities, optimise existing configurations, develop new use cases, and enhance the organisation's overall security monitoring and response capabilities. This role would suit a hands-on Security Engineer, Detection Engineer, SIEM Engineer, or Security Operations specialist with deep Microsoft security expertise and extensive experience working with Sentinel in complex enterprise environments.
Job Responsibility
Act as the technical lead and subject matter expert for Microsoft Sentinel
Review and optimise existing Sentinel deployments, analytics rules, and workbooks
Design, build, and tune threat-detection use cases aligned with current threats
Develop advanced KQL queries for monitoring, threat hunting, and investigations
Integrate new data sources and improve security visibility across the estate
Create and enhance automated response workflows using Logic Apps and Sentinel playbooks
Work closely with Security Operations, Infrastructure, Cloud, and Engineering teams
Support incident investigations and threat-hunting activities
Provide recommendations for improving monitoring coverage, detection fidelity, and operational effectiveness
Requirements
Proven experience as a Microsoft Sentinel SME within enterprise environments
Strong expertise in Microsoft Sentinel architecture, deployment, and administration
Advanced Kusto Query Language (KQL) skills
Strong background in SIEM engineering, detection engineering, and threat hunting
Experience with Microsoft Defender technologies including Defender XDR, Defender for Endpoint, Defender for Identity, and Defender for Cloud
Experience building automation and orchestration workflows using Logic Apps
Good understanding of Azure security services and cloud-native security controls
Strong knowledge of security operations, incident response, and cyber defence principles
Nice to have
Financial Services, Banking, Insurance, or other highly regulated environments
MITRE ATT&CK mapping and detection engineering methodologies
PowerShell and/or Python scripting
Microsoft Security certifications (SC-200, AZ-500, SC-100)