Leave us your email address and we'll send you all the new jobs according to your preferences.

Sentinel SecOps Engineer - Sentinel, KQL, EDR, SOC Tooling

Posted 2 days 13 hours ago by InfraView Ltd

Permanent
Not Specified
Other
London, United Kingdom
Job Description

Jobs Search

Type All

Job Area All

Sentinel SecOps Engineer - Sentinel, KQL, EDR, SOC Tooling
London - Hybrid (3 days in the office)
£450 - £500 p/day Outside IR35

Sentinel SecOps Engineer - Sentinel, KQL, EDR, SOC Tooling - London (3 days onsite) - £450 - £500 p/day Outside IR35

I am working with an exceptional Microsoft Security Solution Provider, and they have an urgent requirement for a Sentinel SecOps Engineer to join their onsite team at one of their longest standing Financial Services clients in the Bank area of London.

They have recently rolled out Sentinel as the SIEM including for Endpoint and they currently have many log sources going into it - Forcepoint, Citrix and Fortinet being some of them. You will need to build all the analytical rules within the log sources and help to support the entire estate.

It is essential that you have exceptional KQL skills, not just be able to follow code, but create it from scratch and spot errors and changes in code as and when you review it. They need someone who is hungry to find the next issue and solve it or create something new to improve. Any EDR experience would be beneficial, preferably Windows-based.

You will be expected on site 3 days a week; working hours are 9-5.30/6, with the remainder of the week working from home. This arrangement may reduce to 2 days later in the contract, but this is not guaranteed.

Required:

  • Exposure working with a previous managed security provider or within an MSSP environment
  • Strong working knowledge of KQL (essential)
  • Experience using SOC tooling (SIEM and EDR solutions) (essential)
  • Previous experience working within financial services
  • Experience using ITSM tools
  • Knowledge of the phases in incident response and Cyber Kill Chain
  • Good blue/purple/red team experience

Please hit the button to Apply and/or call Will Martin at at InfraView for further info.

If this role is not for you, please register with us, letting us know your preferences, and we will be in touch when the right role becomes available.

Sentinel SecOps Engineer - Sentinel, KQL, EDR, SOC Tooling - London (3 days onsite) - £450 - £500 p/day Outside IR35

The Cloud & IT Infrastructure space is constantly shifting. Get the latest job opportunities from top IT Solutions Providers delivered to your inbox by registering with InfraView.

Email this Job