Salary
$92k per year
Location
Hybrid (United Kingdom, 9am - 6pm)
Seniority
Senior
Employment
Full-Time
Confirmed on the employer's own hiring board on Oct 5, 2026. First seen by Alion on Sep 3, 2026.
Overview
Company
Impact
Profile match
Matchtech is a UK engineering and technology recruitment agency headquartered in Whiteley near Fareham, Hampshire, placing contract, temporary and permanent staff with clients. Founded in 1984, it covers aerospace, automotive, maritime, defence and security, energy, highways, rail, water and utilities, construction and technology, and also offers managed service, RPO and recruit-train-deploy programmes for employers such as BAE Systems, Leonardo and NATS. Its vacancies, posted on behalf of clients, include civil, mechanical, process and EICA engineers, CAD technicians, software developers, project managers and site staff across the UK.
Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands-on technical position within the Security Operations domain, focused on helping customers improve and automate their SOC functions, tooling, and detection capabilities.
Key Responsibilities:
- Design and deliver detection rulesets across SIEM and XDR platforms
- Develop and tune detection logic using KQL or equivalent query languages
- Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques
- Map customer log sources to detection use cases to assess coverage and identify gaps
- Design and implement SOAR automations, integrations and response workflows
- Develop and document customer incident response playbooks aligned to detection outputs
- Translate threat intelligence and operational learnings into improved detections and automations
- Deliver detection as code pipelines, including structured use case development and versioning approaches
- Produce clear technical and customer-facing deliverables, including detection strategies, use case catalogues and coverage assessments
- Work directly with customers as a trusted technical consultant
- Lead workshops covering detection engineering, use case design and SOC maturity
- Guide customers on improving detection coverage and aligning to MITRE ATT&CK
- Clearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholders
- Work closely with platform onboarding and engineering teams to ensure smooth integration of delivered detections and automations
- Support SOC teams by ensuring delivered outputs are practical, usable and aligned to operational workflows
- Contribute to the continuous evolution of detection use cases, playbooks and automation patterns
- Support development of reusable detection content and delivery standards
- Contribute to lab work, testing and validation of detection approaches
- Identify gaps in telemetry, logging and enrichment, and provide recommendations to strengthen detection outcomes
Job Requirements:
- Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred
- Experience writing detection logic using KQL or similar query languages
- Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar
- Scripting and automation capability using Python, PowerShell or similar, including working with APIs
- Experience designing detection use cases aligned to MITRE ATT&CK
- Strong understanding of detection coverage and how log sources map to the attack lifecycle
- Experience with XDR or EDR platforms such as Microsoft Defender, CrowdStrike or Cortex
- Understanding of cloud environments, particularly Azure, and associated security telemetry
- Experience working in customer-facing or consultancy roles
- Strong communication skills, with the ability to explain technical concepts clearly
Technical Competencies:
- SIEM and XDR platforms, including Microsoft Sentinel, Microsoft Defender, Palo Alto XSIAM or XDR, CrowdStrike and SentinelOne
- SOAR development, including automation and playbook design using platforms such as Palo Alto XSOAR or similar
- Scripting and integration using Python, PowerShell or similar, including API-driven automation
- Detection engineering aligned to MITRE ATT&CK, including use case design, ruleset development and coverage assessment
- Log source mapping and normalisation to support detection use cases
- Network Detection and Response technologies such as Vectra AI, Corelight or similar
- Cloud security and telemetry, particularly within Azure environments
- Threat intelligence integration and enrichment to support detection and response
- Development of customer playbooks and response workflows aligned to SOC operations
- General awareness of emerging technologies, including AI-driven security tooling and their application within detection and response
Job Specifics:
- Location: This is a hybrid role, primarily remote but with a requirement of ad-hoc travel to customer sites and attend the Basingstoke office as required to support delivery, workshops and engagements.
- Hours: Full-time, Monday - Friday, 9:00am - 5:30pm. There is no on-call requirement for this position.
Benefits:
- Salary up to £80,000
- Performance-based bonuses
- Industry-leading benefits
- A collaborative engineering environment
- Exposure to real-world threats and modern detection approaches
- Opportunity to shape Security Operations capabilities
If you are a skilled Security Engineering Consultant looking to join a dynamic and impactful team, we encourage you to apply now and be a part of building a secure and connected future with our client.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,263,866 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Free forever. No card. Under a minute.
Your match
How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.
Recommended for you based on this role
Security
Similar stack
Same company
United Kingdom
≈ $87k – $163k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • London
DevOps
Kubernetes
Cybersecurity
SIEM
Apply
≈ $56k – $134k per year (Estimated) • In office • Full-Time • 3+ years exp • London
Cybersecurity
ISO 27001
NIST CSF
Apply
Incident Response Analyst
1 day ago
≈ $51k – $123k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • London
DevOps
Linux
Windows
Unix
Apply
Senior Security Architect
1 day ago
$79k – $118k per year • Hybrid • Full-Time • Perth
DevOps
Azure
AWS
IAM
Cybersecurity
Zero Trust
Management
Agile
Apply
Information Security Compliance Analyst
9 hours ago
up to $59k per year • Hybrid • Full-Time • Swindon
Cybersecurity
ISO 27001
PCI DSS
SOC 2
Management
Confluence
Jira
Apply
AI Data Engineer
4 days ago
$83k – $138k per year • In office • Full-Time • Bachelor's Degree • Cleveland • Cincinnati • Chicago • Columbus
Python
SQL
PowerShell
Python
pySpark
Databases
Databricks
MS SQL
Azure SQL Database
Microsoft Fabric
AI/ML
Copilot
Spark
AI Agents
DevOps
GitHub Actions
Azure
CI/CD
Git
GitHub
Analytics
Power BI
Azure Data Factory
Apply
$116k – $209k per year • Equity • In office • Full-Time • 7+ years exp • Bachelor's Degree • New York • Herndon • Overland Park • Bellevue
Python
SQL
Analytics
Tableau
Power BI
Apply
Sr. Analyst, Reporting & Decision Support
4 days ago
$78k – $141k per year • Equity • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Overland Park
Python
SQL
Apply
Senior Administrator - SAP BASIS
4 days ago
In office
Databases
SAP HANA
DevOps
GCP
Azure
AWS
Management
ITIL
Apply
In office • 3+ years exp • Bachelor's Degree
Python
SQL
Cybersecurity
CAPA
Apply
Project Manager (Cyber Security)
6 days ago
$86k per year • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • United Kingdom
Apply
OT Cybersecurity Engineer
28 days ago
$79k per year • In office • Full-Time • United Kingdom
IoT
OPC UA
Apply
Cyber Security Consultant
1 month ago
$61k per year • Hybrid • Full-Time • Bristol
Cybersecurity
ISO 27001
Apply
Cyber Security Consultant
1 month ago
$61k per year • Hybrid • Full-Time • Plymouth
Cybersecurity
ISO 27001
Apply
Cyber Security Consultant
1 month ago
$61k per year • Hybrid • Full-Time • Portsmouth
Cybersecurity
ISO 27001
Apply
Field Service Engineer - Systems
9 hours ago
≈ $35k – $65k per year (Estimated) • In office • Full-Time • United Kingdom
DevOps
Amazon ECS
Apply
Apply
Head of Training – European Helicopter Training
9 hours ago
≈ $42k – $87k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Oslo
Apply
Desktop Engineering Lead
9 hours ago
≈ $32k – $70k per year (Estimated) • Hybrid • Full-Time • United Kingdom
Apply
Head of Clinical Partnerships Assurance
9 hours ago
up to $88k per year • Hybrid • Full-Time • United Kingdom
Apply
This is one of many
1,263,866 more open roles from verified company boards, updated every day.

