Senior Detection Engineer

Senior Detection Engineer

Full-Time 55000 - 55000 £ / year (est.) Home office (partial)
Our Future Health UK

At a Glance

  • Tasks: Create innovative threat detections and collaborate with a dynamic security team.
  • Company: Join Our Future Health, a pioneering tech company focused on health innovation.
  • Benefits: Competitive salary, generous holidays, pension scheme, and wellbeing support.
  • Other info: Flexible working arrangements and a supportive, diverse workplace culture.
  • Why this job: Make a real impact in cybersecurity while shaping the future of health.
  • Qualifications: Proficient in KQL, experience with Microsoft Sentinel, and a passion for security.

The predicted salary is between 55000 - 55000 £ per year.

We're looking for a Detection Engineer to join our expanding Information Security team who thrives on innovation, loves working across disciplines, and brings new ideas to the team. This is your chance to take ownership, experiment, and grow into a role with the opportunity to make a real impact. This isn't your average SOC role. At Our Future Health, the "boring bits" of the SOC are outsourced, leaving you with the exciting, high‑impact work that shapes how we detect and respond to threats at scale.

You'll collaborate closely with our in-house Threat team and our outsourced SOC partner, building unique detection capabilities that go beyond just SIEM detections. Think KQL scripting, Microsoft Sentinel, Azure, Kubernetes, and cloud‑native log sources, all while applying MITRE frameworks and helping to configure and tune other core security controls like DLP to keep us ahead of the threat landscape. If you want to design detections that matter, and be part of something unique that is the first of its kind at this scale, then this is the role for you.

At Our Future Health, our mission is to transform the prevention, detection and treatment of conditions such as dementia, cancer, diabetes, heart disease and stroke. We're looking for people to join us on our journey. If you're looking for a new challenge where you can contribute to helping future generations live in good health for longer, then we're keen to speak with you.

What You'll Be Doing

  • Developing new threat-led detections in collaboration with our threat team based on both threat intelligence and the results of threat hunts.
  • Creating novel analytic methods and techniques for incident detection.
  • Working with our MSP provided SOC to maintain our detection catalogue and tune existing rules.
  • Developing and tuning Data Loss Prevention, Insider Risk Management and other types of security rules within Microsoft Purview and other key security monitoring tools.
  • Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided, detections and other types of engineering work are delivered to the appropriate standard and that the maturity (inc. efficiency) of our security monitoring is continually improving.
  • Supporting the development of automated custom reports on security operational performance and broader security topics (using Sentinel workbooks).
  • Collaborating with wider tech and security teams on the appropriate security monitoring for our various systems, including cloud platforms, SaaS applications and in-house developed systems.
  • Documenting security processes and security tool low-level design/configuration.
  • Contributing to the development of security service delivery and operation documentation.
  • Supporting the security engineers, threat analysts and wider security team with their various responsibilities, including achieving and maintaining ISO 27001 certification and anything that involves KQL.

What You Won't Be Doing

  • Working in a siloed environment with no freedom to make decisions.
  • Working in a place where you can't see the impact your expertise makes.

Requirements

  • Highly proficient in writing KQL and ideally some level of proficiency in Python and Terraform.
  • Significant hands‑on experience with Microsoft Sentinel.
  • Experience with Microsoft's Defender suite, in particular Defender for Endpoints and Defender for O365.
  • Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities.
  • Experience with Microsoft Purview tooling, in particular MPIP and Purview Data Loss Prevention.
  • Experience with cloud-native logging (in particular Azure and Kubernetes).
  • Experience of an ‘everything-as-code', or at least a ‘detection-as-code' approach, including CI/CD pipelines.
  • Exposure to working with/inside an MSP SOC.
  • Exposure to Agile working.
  • Knowledge of attacker Tactics, Techniques and Procedures (TTPs).
  • Knowledge of statistics, data science and AI/ML, in particular when applied to cyber security.
  • Knowledge of ISO 27001.
  • Desire to be part of a small fast-paced team.
  • Relevant certifications, such as: Microsoft certifications (MS‑500, AZ‑500, SC‑200, SC‑300, SC‑400), CompTIA Security+, GIAC Security Operations Certified (GSOC), Cloud Security Alliance CCSK.

Benefits

  • Salary from £55,000 per annum.
  • Generous Pension Scheme – We invest in your future with employer contributions of up to 12%.
  • 30 Days Holiday + Bank Holidays – Enjoy a generous holiday allowance with the flexibility to take bank holidays when it suits you.
  • Enhanced Parental Leave – Supporting you during life's biggest moments.
  • Cycle to Work Scheme – Save 25‑39% on a new bike and accessories through salary sacrifice.
  • Home & Tech Savings – Get up to 8% off on IKEA and Currys products, spreading the cost over 12 months through salary sacrifice.
  • £1,000 Employee Referral Bonus – Know someone amazing? Get rewarded for bringing them on board!
  • Wellbeing Support – Access to Mental Health First Aiders, plus 24/7 online GP services and an Employee Assistance Programme for you and your family.
  • A Great Place to Work – We have a lovely Central London office in Holborn, and offer flexible and remote working arrangements.

Join us – let's prevent disease together. At Our Future Health, we recognise the importance of having a diverse workforce and ensuring that all candidates, regardless of their background, have equitable access to our application process. We proactively encourage applicants who identify as having a disability, neurodiversity, or long‑term health conditions to let us know if they require any reasonable adjustments as part of their application process. If you do require any reasonable adjustments, please email us at talent@ourfuturehealth.org.uk.

Senior Detection Engineer employer: Our Future Health UK

At Our Future Health, we pride ourselves on being an innovative employer that empowers our employees to take ownership of their work and make a meaningful impact in the field of information security. With a collaborative culture, generous benefits including a robust pension scheme and enhanced parental leave, and a commitment to employee growth through unique projects and cutting-edge technologies, we offer a rewarding environment for those looking to advance their careers while contributing to the health of future generations. Our central London location provides a vibrant workspace with flexible working arrangements, making it an ideal place for passionate professionals to thrive.
Our Future Health UK

Contact Detail:

Our Future Health UK Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Senior Detection Engineer

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your KQL scripts, Python projects, or any cool detection methods you've developed. This gives potential employers a taste of what you can bring to the table.

✨Tip Number 3

Prepare for interviews by brushing up on common questions related to threat detection and incident response. Practice explaining your thought process when developing detections or tuning security rules – it’ll show you’re ready to hit the ground running!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are genuinely interested in joining our mission to transform health.

We think you need these skills to ace Senior Detection Engineer

KQL Scripting
Microsoft Sentinel
Python
Terraform
Data Loss Prevention (DLP)
Microsoft Defender Suite
Microsoft Entra ID
Cloud-Native Logging
Azure
Kubernetes
Detection-as-Code
CI/CD Pipelines
Agile Working
Knowledge of Attacker Tactics, Techniques and Procedures (TTPs)
ISO 27001

Some tips for your application 🫡

Show Your Passion: When writing your application, let your enthusiasm for the role shine through! We want to see how excited you are about the opportunity to innovate and make a real impact in our Information Security team.

Tailor Your Experience: Make sure to highlight your relevant experience with KQL, Microsoft Sentinel, and any other tools mentioned in the job description. We love seeing how your skills align with what we're looking for, so don’t hold back!

Be Clear and Concise: Keep your application straightforward and to the point. We appreciate clarity, so avoid jargon and focus on communicating your ideas effectively. Remember, we’re looking for someone who can collaborate across disciplines!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity. Let’s get started on this journey together!

How to prepare for a job interview at Our Future Health UK

✨Know Your KQL Inside Out

As a Senior Detection Engineer, you'll need to demonstrate your proficiency in KQL. Brush up on your KQL skills and be ready to discuss specific queries you've written or optimised. Prepare examples of how your KQL scripts have improved detection capabilities in previous roles.

✨Showcase Your Collaboration Skills

This role involves working closely with various teams, including the Threat team and MSP SOC. Be prepared to share experiences where you've successfully collaborated across disciplines. Highlight any projects where teamwork led to innovative solutions or improved security outcomes.

✨Understand the Threat Landscape

Familiarise yourself with current threats and trends in cybersecurity. Be ready to discuss recent incidents or threat intelligence that could impact the organisation. Showing that you stay updated on TTPs will demonstrate your commitment to proactive security measures.

✨Prepare for Technical Questions

Expect technical questions related to Microsoft Sentinel, Azure, and cloud-native logging. Review the tools mentioned in the job description and be ready to explain how you've used them in past roles. Consider preparing a mini-case study on a detection challenge you've faced and how you resolved it.

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>