Nomios logo
NomiosPosted 1 month ago

Senior Security Engineering Consultant

HybridBasingstoke, England, United Kingdom

Full TimeSenior Level

Job Summary

Design and deliver detection rulesets across SIEM and XDR platforms, developing logic using KQL and implementing SOAR automations and response workflows. Map customer log sources to detection use cases aligned with MITRE ATT&CK, then document incident response playbooks and translate threat intelligence into improved detections. Lead workshops with customers to guide detection coverage improvements and collaborate with platform engineering teams to ensure practical, usable outputs. This hybrid role requires 70-80% remote work with occasional travel to customer sites and the Basingstoke office. Full-time hours are Monday through Friday, 9:00am to 5:30pm, with no on-call requirement. You will work within the Security Operations Team, shaping how customers build and run their Security Operations capabilities.

Required Qualifications

  • Strong hands-on experience with SIEM engineering, including developing and tuning detection rules
  • Experience writing detection logic using KQL or similar query languages
  • Proven experience designing and implementing SOAR automations and playbooks
  • Scripting and automation capability using Python, PowerShell or similar, including working with APIs
  • Experience designing detection use cases aligned to MITRE ATT&CK
  • Strong understanding of detection coverage and how log sources map to the attack lifecycle
  • Experience with XDR or EDR platforms such as Microsoft Defender, CrowdStrike or Cortex
  • Understanding of cloud environments, particularly Azure, and associated security telemetry
  • Experience working in customer-facing or consultancy roles
  • Strong communication skills, with the ability to explain technical concepts clearly
  • 70% to 80% percent of the time remote with requirement to travel to customer sites and attend the Basingstoke office as required

Desired Qualifications

  • Microsoft Sentinel
  • Logic Apps
  • Cortex XSOAR
  • Microsoft Defender
  • CrowdStrike
  • Palo Alto XSIAM or XDR
  • SentinelOne
  • Vectra AI
  • Corelight
  • AI-driven security tooling

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce