Microsoft Security Operations

Overview

We are now opening a Microsoft security operations line. The first engagement is a 24/7 white-labelled managed SOC for a UK client on a Microsoft 365 centric estate, up to 500 nodes, delivered as Sentinel-based MXDR.

You build that service, then hand it to our managed services team to run. After that, you are the person who grows this capability across the rest of our client base. This is a practice investment, not a single-project contract.

Job Description

Personal Characteristics :

Strong portfolio and excellent attitude.

Must be self-confident to work in a Team and to handle the responsibilities individually as well

Should be a good listener/ Can articulate well / Good Communication Skills

Ability to work with teams across organizational boundaries, different cultures and different time zones in a virtual environment

Delivery oriented and able to work under strict deadlines

Key Responsibilities :

Run discovery and gap analysis workshops with clients. Scope the estate, size the node count, agree log sources, and produce the assessment that the commercial quote rests on.

Design and stand up Microsoft Sentinel end to end: data connectors, data collection rules, analytics rules, watchlists, UEBA, workbooks, Logic App playbooks, and ingestion cost tuning.

Deploy and tune Defender for Endpoint. Configure Defender for Office 365, Identity and Cloud Apps.

Build detection content mapped to MITRE ATT&CK, and write the triage, escalation and containment runbooks behind it.

Stand up 24/7 operations with our L1 and L2 team: shift handover, SLA definitions, escalation paths and DFIR handoff.

Produce audit-grade monitoring and detection evidence for client compliance frameworks. Our clients use this output as certification evidence, so it has to survive an auditor.

Deliver multi-tenant and white-labelled services through Microsoft Lighthouse, where the end client never sees us.

Evaluate and quote third party MDR platforms such as SentinelOne where the native Microsoft stack is not the right fit.

Train and certify the existing managed services team. Knowledge transfer is a deliverable of this role, not a courtesy.

Support presales: scoping calls, effort and cost models, and technical responses to tenders.

What you need to have done before:

Stood up at least one greenfield Sentinel tenant end to end, and can walk us through the decisions you made and the ones you would change.

KQL fluency. We will assess this live.

Defender for Endpoint deployment, policy and tuning at scale.

Incident response in practice, from triage through containment to DFIR handoff.

Multi-tenant or white-label delivery inside an MSSP or managed service.

SC-200 certification.

Enough client presence to run a discovery workshop with a client leadership team on your own.

A track record of documenting what you built and training other people to run it.

Evidence packs for UK frameworks: Cyber Essentials, DCC, NIST CSF or
ISO 27001.

Azure platform security: landing zones, Azure Policy, Entra ID, Key Vault.

Automation with Logic Apps, PowerShell, Bicep or Terraform.

AWS security exposure such as GuardDuty and Security Hub. We are an AWS-first house and the two practices will sit side by side.

Who this role is not for:

A tier one SOC analyst. We already have monitoring capacity. The gap is the engineering above it.

A GRC or audit consultant. That ground is already covered internally.

An Azure infrastructure architect who has not done detection engineering.

Skills & Requirements

Microsoft Sentinel, KQL, Microsoft Defender For Endpoint, Microsoft Defender For Office 365, Microsoft Defender For Identity, Microsoft Defender For Cloud Apps, MITRE ATT&CK, Incident Response, DFIR, Detection Engineering, Microsoft Lighthouse, MXDR, MSSP, Cybersecurity Operations, Azure Security, Azure Landing Zones, Azure Policy, Entra ID, Key Vault, Logic Apps, PowerShell, Bicep, Terraform, AWS GuardDuty, AWS Security Hub, SC-200, Cyber Essentials, DCC, NIST CSF, ISO 27001, SIEM, UEBA, Security Monitoring, Threat Detection, Security Automation, Presales, Client Discovery, SOC Engineering, Multi-Tenant Security, White-Label Security Services

Apply Now

Join Our Community

Let us know the skills you need and we'll find the best talent for you