Senior Detection Engineer (Consultancy) in Reading

Senior Detection Engineer (Consultancy) in Reading

Reading Full-Time No working from home possible
F

Senior Detection Engineer (Consultancy) β€” Remote (Southern England)

Location: Home-based across the South β€” client site roughly once a fortnight Salary: Β£70,000 + Β£5,000 car allowance + Β£15,000 bonus (Β£90,000 total package)

Detection engineering, done properly

This isn't a deployment role and it isn't a monitoring role. You'll spend your time on the thing most detection engineers never get enough of: designing, writing and tuning the detection logic itself.

You'll work across customer environments as part of an established Professional Services team, alongside the SOC Engineering function. Because this is a managed security service provider, you'll see more estates, more log sources and more genuinely different problems in a year than most in-house roles offer in five.

The split is roughly 80/20 β€” the large majority of your week is hands-on detection and automation work, with the remainder client-facing: workshops, coverage assessments and walking customers through what you've built.

Home-based, with client site visits roughly every couple of weeks. No on-call rota. No clearance requirement.

What you'll be doing

  • Designing and building detection rulesets across SIEM and XDR platforms
  • Writing and tuning detection logic in KQL, cutting false positives without losing coverage
  • Mapping customer log sources against use cases to identify and close coverage gaps
  • Designing use cases aligned to MITRE ATT&CK
  • Building SOAR automations and automated response workflows
  • Writing incident response playbooks for customers
  • Owning the detection-as-code approach β€” pipelines, version control, deployment
  • Running workshops, coverage assessments and use case catalogues as customer deliverables

What we're looking for

  • Hands-on SIEM engineering experience, ideally Microsoft Sentinel
  • Confident KQL β€” this is the core of the role
  • SOAR playbook design in Azure Logic Apps, Cortex XSOAR or similar
  • Scripting in Python or PowerShell, and comfort working with APIs
  • Use case design against MITRE ATT&CK
  • Working knowledge of XDR/EDR platforms and Azure telemetry sources
  • Some exposure to NDR tooling such as Vectra AI or Corelight is a bonus

Consultancy or customer-facing experience is valuable, but if you've built strong detection engineering skills in an in-house SOC and want to move into a client-facing role, we'd still like to hear from you.

What's on offer

  • Β£70,000 base, Β£5,000 car allowance and a Β£15,000 bonus
  • Home-based across Southern England, with client visits around once a fortnight
  • No on-call, no shift rota
  • No security clearance required
  • Roughly 80% hands-on engineering, 20% client-facing
  • Technical ownership of the detection-as-code practice
  • Certification and training support with a clear progression path
  • Exposure to enterprise security estates across multiple industries

How to apply

Apply through Reed with an up-to-date CV, or get in touch for a confidential conversation.

Fazer Recruitment is acting as an employment agency in relation to this vacancy.

F

Contact Details:

Fazer Recruitment Careers Recruitment Team