Skip to content
← Back to job listings

Security Content Engineer

BlueVoyant · United Kingdom

RemoteImported listingfull-time12 days ago

About The Role

Join BlueVoyant, a leading cybersecurity company, as a Security Content Engineer. In this fully remote role, you will develop, tune, and maintain detection and automation content to protect our global clients. You will own a portfolio of content, conduct advanced tuning and optimization, lead threat-informed research, develop scalable automation, serve as a technical resource, and improve team frameworks. The ideal candidate will have 5-8 years of experience in detection engineering or security operations, deep expertise in the Microsoft security stack, and strong analytical and problem-solving skills.

  • Autonomously develop, test, and maintain high-fidelity detection logic in KQL for the Microsoft Sentinel environment.
  • Perform independent and complex global tuning to improve SOC efficiency and outcomes, proactively identifying and resolving sources of alert fatigue.
  • Independently research emerging threats, attack vectors, and high-risk vulnerabilities to design and develop proactive detection strategies.
  • Proven ability to operate with a high degree of autonomy, managing competing priorities and complex projects with minimal supervision
  • In-depth knowledge of attacker TTPs, the MITRE ATT&CK framework, and modern blue team operations
  • Strong collaboration and communication skills, with the ability to clearly explain complex technical concepts
  • 5-8 years of direct experience in Detection Engineering, Security Operations, or a similar role with a heavy focus on content creation
  • Deep, hands-on expertise with the Microsoft security stack, including Microsoft Sentinel, Microsoft 365 Defender, and Logic Apps
  • Strong, demonstrated experience automating security workflows using SOAR platforms, APIs, or scripting languages (Python, PowerShell)
  • Excellent analytical and problem-solving skills, with experience in deep log analysis and digital forensics
  • High proficiency in Kusto Query Language (KQL), with proven experience writing complex, optimized queries for detection and hunting
  • Experience in a large-scale Managed Detection and Response (MDR) environment
  • Familiarity with CI/CD pipelines and version control (Git) for managing "detections-as-code."
  • Advanced industry certifications such as GCIH, GDAT, GCFA, or OSCP

This is an external listing. JobSpring does not represent or verify the employer. Report this listing