Overview
Cyber Security Consultant Jobs in London Area, United Kingdom at Franklin Fitch
Title: Cyber Security Consultant
Company: Franklin Fitch
Location: London Area, United Kingdom
Cyber Security Consultant | £55,000 – £65,000 + bonus | Hybrid | MSP
This is a customer-facing consultancy role where you'll work with a wide range of organisations to design, develop and optimise detection and response capabilities across leading SIEM, XDR and SOAR technologies. You'll combine deep technical expertise with strong consulting skills, helping customers improve their security maturity through practical, scalable solutions.
What you'll be doing
You'll play a key role in delivering detection engineering engagements, including:
- Designing and implementing high-quality detection rules across SIEM and XDR platforms.
- Creating and optimising detection logic using KQL and other query languages.
- Developing detection use cases aligned with the MITRE ATT&CK framework and current threat techniques.
- Assessing customer telemetry and identifying opportunities to improve visibility and detection coverage.
- Building SOAR automations, integrations and response workflows to reduce manual effort.
- Developing incident response playbooks that support effective Security Operations Centre (SOC) processes.
- Applying threat intelligence to continuously improve detections and response capabilities.
- Promoting a Detection-as-Code approach, ensuring detection content is scalable, version controlled and repeatable.
- Producing clear technical documentation, detection strategies and coverage assessments for customers.
Alongside technical delivery, you'll act as a trusted advisor by leading workshops, presenting recommendations to stakeholders and helping customers develop long-term detection strategies.
What we're looking for
We're interested in security professionals who enjoy solving complex problems and working closely with customers.
You'll ideally have experience with:
- SIEM engineering, preferably Microsoft Sentinel.
- Detection engineering and rule development using KQL or similar languages.
- SOAR platforms such as Microsoft Logic Apps, Cortex XSOAR or equivalent.
- Python, PowerShell or other scripting languages for automation and API integration.
- MITRE ATT&CK and threat-informed detection engineering.
- XDR/EDR technologies including Microsoft Defender, CrowdStrike, Cortex XDR or SentinelOne.
- Azure security monitoring and cloud telemetry.
- Log source onboarding, data normalisation and detection coverage analysis.
- Threat intelligence integration and enrichment.
- Customer-facing consultancy or professional services environments.
Please apply now for immediate consideration!