Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling
Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling

Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling

London Freelance Home office (partial)
I

At a Glance

  • Tasks: Join a dynamic team to build analytical rules and support security operations.
  • Company: Work with a leading Microsoft Security Solution Provider in the financial sector.
  • Benefits: Enjoy hybrid work, competitive pay, and opportunities for professional growth.
  • Why this job: Be part of an innovative environment tackling real-world security challenges.
  • Qualifications: Strong KQL skills and experience in SOC tooling are essential.
  • Other info: Onsite work required 3 days a week, with potential for remote flexibility.

Jobs Search

Type All

Job Area All

Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC ToolingLondon – Hybrid (3 days in the office)£450 – £500 p/day Outside IR35

Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling – London (3 days onsite) – £450 – £500 p/day Outside IR35

I am working with an exceptional Microsoft Security Solution Provider, and they have an urgent requirement for a Sentinel SecOps Engineer to join their onsite team at one of their longest standing Financial Services clients in the Bank area of London.

They have recently rolled out Sentinel as the SIEM including for Endpoint and they currently have many log sources going into it – Forcepoint, Citrix and Fortinet being some of them. You will need to build all the analytical rules within the log sources and help to support the entire estate.

It is essential that you have exceptional KQL skills, not just be able to follow code, but create it from scratch and spot errors and changes in code as and when you review it. They need someone who is hungry to find the next issue and solve it or create something new to improve. Any EDR experience would be beneficial, preferably Windows-based.

You will be expected on site 3 days a week; working hours are 9-5.30/6, with the remainder of the week working from home. This arrangement may reduce to 2 days later in the contract, but this is not guaranteed.

Required:

  • Exposure working with a previous managed security provider or within an MSSP environment
  • Strong working knowledge of KQL (essential)
  • Experience using SOC tooling (SIEM and EDR solutions) (essential)
  • Previous experience working within financial services
  • Experience using ITSM tools
  • Knowledge of the phases in incident response and Cyber Kill Chain
  • Good blue/purple/red team experience

Please hit the button to Apply and/or call Will Martin at 020 3950 9977 at InfraView for further info.

If this role is not for you, please register with us, letting us know your preferences, and we will be in touch when the right role becomes available.

Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling – London (3 days onsite) – £450 – £500 p/day Outside IR35

The Cloud & IT Infrastructure space is constantly shifting. Get the latest job opportunities from top IT Solutions Providers delivered to your inbox by registering with InfraView.

#J-18808-Ljbffr

Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling employer: InfraView Ltd

Join a leading Microsoft Security Solution Provider that values innovation and expertise in the heart of London’s financial district. With a hybrid work model, competitive daily rates, and a culture that fosters continuous learning and problem-solving, this role offers an exciting opportunity to enhance your skills in a dynamic environment. You'll be part of a collaborative team dedicated to tackling complex security challenges, ensuring both personal and professional growth.
I

Contact Detail:

InfraView Ltd Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling

Tip Number 1

Familiarise yourself with Microsoft Sentinel and its functionalities. Understanding how to effectively use this SIEM tool will not only boost your confidence but also demonstrate your commitment to the role during any discussions.

Tip Number 2

Brush up on your KQL skills by working on sample queries and analytical rules. Being able to showcase your ability to create and troubleshoot KQL code will set you apart from other candidates.

Tip Number 3

Gain insights into the financial services sector, especially regarding security challenges and compliance requirements. This knowledge will help you speak more fluently about the specific needs of the client during interviews.

Tip Number 4

Network with professionals in the cybersecurity field, particularly those who have experience with SOC tooling and EDR solutions. Engaging with industry peers can provide valuable insights and potentially lead to referrals.

We think you need these skills to ace Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling

Strong knowledge of KQL
Experience with SIEM solutions
Experience with EDR solutions
Familiarity with SOC tooling
Understanding of incident response phases
Knowledge of the Cyber Kill Chain
Experience in a managed security service provider (MSSP) environment
Previous experience in financial services
Proficiency in ITSM tools
Blue team, purple team, and red team experience
Analytical problem-solving skills
Attention to detail
Ability to create and review code
Strong communication skills
Adaptability to changing environments

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights your experience with KQL, SOC tooling, and any relevant EDR solutions. Use specific examples from your previous roles to demonstrate your skills and achievements in these areas.

Craft a Strong Cover Letter: In your cover letter, express your enthusiasm for the role and the company. Mention your experience in financial services and how it relates to the position. Be sure to include your problem-solving mindset and eagerness to tackle challenges.

Showcase Relevant Skills: Clearly outline your technical skills related to Sentinel, KQL, and incident response phases. If you have experience with ITSM tools or working in an MSSP environment, make sure to highlight that as well.

Proofread Your Application: Before submitting, carefully proofread your application for any spelling or grammatical errors. A polished application reflects your attention to detail, which is crucial for a role in security operations.

How to prepare for a job interview at InfraView Ltd

Showcase Your KQL Skills

Since exceptional KQL skills are essential for this role, be prepared to discuss your experience in detail. Bring examples of analytical rules you've built and be ready to demonstrate your ability to create code from scratch.

Understand the Financial Services Sector

Having previous experience in financial services is crucial. Familiarise yourself with the specific security challenges faced by this sector and be ready to discuss how your background can help address these issues.

Familiarity with SOC Tooling

Make sure you can talk about your experience with SIEM and EDR solutions. Be prepared to explain how you've used these tools in past roles and how they can be leveraged to improve security operations.

Demonstrate Problem-Solving Mindset

The company is looking for someone who is hungry to find and solve issues. Prepare to share examples of past challenges you've encountered in a similar role and how you approached solving them creatively.

Sentinel SecOps Engineer – Sentinel, KQL, EDR, SOC Tooling
InfraView Ltd
I
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>