
Remote opportunity at
BlueVoyantSenior Security Content Engineer
BlueVoyant is seeking a Senior Security Content Engineer to join its Threat Fusion Cell on a remote basis within the United Kingdom. This role centers on…
Career Tools
AI Summary
This remote UK-based role focuses on creating automated security analytics, developing custom detection logic, and building data visualizations for client threat defense. Day-to-day tasks include fine-tuning alerts to reduce false positives, researching emerging cyber threats, and collaborating with external clients and internal operations teams. A senior engineer in this position also automates onboarding processes and mentors junior team members.
About This Role
BlueVoyant is seeking a Senior Security Content Engineer to join its Threat Fusion Cell on a remote basis within the United Kingdom. This role centers on building automated security analysis solutions, creating detection logic, and designing visualizations that help clients gain actionable security insights. The ideal candidate will work closely with customers and internal teams to enhance security operations, research emerging threats, and refine global detection capabilities. The position suits…
Job Description
BlueVoyant is seeking a Senior Security Content Engineer to join its Threat Fusion Cell on a remote basis within the United Kingdom. This role centers on building automated security analysis solutions, creating detection logic, and designing visualizations that help clients gain actionable security insights. The ideal candidate will work closely with customers and internal teams to enhance security operations, research emerging threats, and refine global detection capabilities.
The position suits an experienced cybersecurity professional who enjoys working at the intersection of threat research, detection engineering, and security operations. Responsibilities span across designing complex detection analytics, building onboarding automation, fine-tuning alerts to minimize false positives, and mentoring junior team members. Candidates must possess the legal right to work in the UK.
BlueVoyant operates as an AI-driven cybersecurity firm dedicated to protecting networks, identities, vendors, and digital footprints. Founded in 2017 and led by a team of former government cyber officials and private sector leaders, the organization delivers unified defense solutions leveraging real-time datasets and proprietary intelligence. Employees gain access to competitive compensation and a comprehensive benefits package supporting professional development and wellbeing.
Responsibilities
- Enrich security signals to boost operational efficiency and outcomes for security operations centers.
- Investigate threat actors and attack vectors to create detection content for emerging threats.
- Build and design automation content for product onboarding.
- Create complex detection analytic rules to expand global detection capabilities.
- Help clients test and adjust detection logic to decrease alert fatigue and false positives.
- Perform high-level global tuning for complex alerts.
- Identify and promote reusable assets such as rules, dashboards, and automations across clients.
- Lead log ingestion integration projects to minimize noise.
- Produce research-driven queries, signatures, rules, and knowledge base documents.
- Build supplemental detection coverage for exploitable high-risk vulnerabilities.
- Establish security policies, automation frameworks, and operating procedures.
- Interact routinely with client IT departments to share guidance and ensure operational readiness.
- Contribute to incident response documentation, processes, and reporting.
- Mentor less experienced team members.
Requirements
- Right to work in the United Kingdom.
- Expert experience writing detection algorithms or signatures.
- Expert proficiency in analyzing event logs and identifying indicators of compromise.
- Hands-on experience with Microsoft Azure, Sentinel, Defender, and related tools.
- Deep familiarity with Sentinel Incidents, Workbooks, Hunting Queries, Notebooks, and Kusto Query Language or similar tools.
- Familiarity with complex JSON data structures and development tools such as Git, IDEs, and CI/CD pipelines.
- Expert scripting capabilities in Python, Ruby, or similar languages.
- Background in blue team operations and digital forensics.
- Advanced grasp of network protocols and infrastructure.
- Ability to convert client requirements into functional technical solutions.
- Strong understanding of SIEM platforms, SOAR platforms, API integrations, EDR, log analysis, malware detection, network monitoring, case management systems, and the Atlassian Suite.
Qualifications
- Background in penetration testing, detection engineering, or intrusion analysis.
- Ten or more years of experience in information technology or cybersecurity centered on SIEM and detection content.
- Relevant certifications including Microsoft 365 Certified Security Administrator Associate, GCFA, GCFE, or OSCP.
- Bachelor's degree in a relevant field or equivalent professional experience and certifications.
- Master's degree in Cybersecurity, Computer Science, Information Assurance, or a related technical discipline.
Core Skills
Benefits
- Competitive compensation package.
- Comprehensive benefits covering wellbeing, professional development, and career advancement.
Frequently Asked Questions
Answers are based only on the employer’s listing; where it doesn’t say, neither do we.
Where is this job located?
This position is remote, specifically based in the United Kingdom.
What are the work authorization requirements?
All applicants must have the legal right to work in the United Kingdom prior to starting employment.
What is the salary for this position?
The source posting does not specify a salary.
What department does this role sit within?
This role is part of the Threat Fusion Cell department at BlueVoyant.
Role DNA (AI assessment)
High technical complexity and frequent stakeholder communication combine to create a balanced, fast-moving senior role requiring both deep threat research expertise and strong collaborative skills.
Salary Analysis
No salary was provided in the job posting, but estimated market rates for a Senior Security Content Engineer in the UK typically range from £70,000 to £105,000.
Employer-Listed Salary
Not disclosed
As stated in this job posting.
AI salary estimate (not from the employer)
AI-estimated market range based on role, seniority, and location — not a guaranteed offer, and independent of the employer's own figure above.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.