Senior Security Engineer
AI in this role
You’ll design and deliver Sentinel-led detection and response, build smart SOAR automation, and shape XDR strategies that drive real impact. This is hands-on consultancy work in a collaborative environment that values innovation, knowledge sharing, and high-quality delivery.
Key Responsibilities
Microsoft Sentinel engineering:Design, deploy and optimise Sentinel environments, including data connectors, normalisation, analytics rules, UEBA, watchlists, workbooks, and cost-conscious ingestion strategies
Automation & SOAR:
Develop and implement pragmatic SOAR playbooks using Logic Apps and Power Automate to reduce manual effort and improve response times
XDR implementation:
Deploy and optimise Microsoft Defender XDR across endpoints, identity, email, and cloud. Align detections with MITRE ATT&CK and relevant threat scenarios
Threat hunting & response:
Use KQL for proactive threat hunting, support incident triage, and continuously improve detection use cases in collaboration with SOC teams
Data protection & compliance:
Advise on Microsoft Purview, Information Protection, and DLP, supporting clients from design through to implementation and rollout
Client delivery:
Translate technical solutions into business value through roadmaps, reporting, and stakeholder communication
Knowledge sharing:
Support and mentor colleagues, contribute to reusable assets, and share best practices within Fox-IT
Business development:
Support pre-sales activities, including scoping, proposals, and advising clients on security strategy
Skills, Knowledge & Expertise
Strong experience delivering Microsoft Security solutions, including:- Microsoft Sentinel (essential)
- Microsoft Defender XDR
- SOAR (Logic Apps / Power Automate)
- Purview / DLP
- Solid skills in KQL, scripting (PowerShell), and version control (Git)
- Experience with cost optimisation in Azure (ingestion, retention, table selection)
Proven Consulting Capability:
- Client workshops
- Architecture design
- Stakeholder management
- Clear and structured reporting
- Understanding of security standards and frameworks (ISO 27001, NIST, GDPR) within a cloud context
Nice-to-have Skills:
- Infrastructure as Code (ARM, Bicep, Terraform)
- Entra ID and Conditional Access
- Microsoft Defender for Cloud, Intune
- MITRE ATT&CK mapping
- Incident response experience
- Certifications such as SC-200, SC-100, CISSP, CISM, ISO 27001
- Focusing on Clients and Customers.
- Working as One NCC.
- Always Learning.
- Being Inclusive and Respectful.
- Delivering Brilliantly.
How we rate this
Senior Security Engineer at NCC Group rates 36 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Classification
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Get new AI jobs by email
One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
BT Customer Site, BT Customer Site, United Kingdom | Site D, Sinfin, Derby, United Kingdomjust now
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step