CyberMXDR Engineer
If you’re interested in joining a trailblazing company where you’ll be recognized for who you are, rewarded for your performance, and celebrated for your achievements, then apply today!
Join our global team of extraordinary technologists!
BUI is an industry-leading technology consultancy and a Microsoft Azure Expert MSP, Microsoft Solutions Partner for the Microsoft Cloud, and Microsoft Security Experts MXDR Partner. We deliver advanced solutions across Cloud, Security, Networking, and Managed Services, supporting mid-market and enterprise organisations globally.
Our work is guided by three principles: Innovation, Delivery, and Results. At BUI, you’ll collaborate with highly skilled architects, consultants, developers, engineers, and security specialists to design and deliver sophisticated solutions that help our customers modernise, transform, and scale their businesses.
We offer an environment where expertise is valued, performance is recognised, and contributions are visible. If you’re looking to apply your skills in a business that combines technical excellence with meaningful impact, we invite you to apply.
The position
Cyber MXDR Engineer
Role Purpose
The Cyber MXDR Engineer builds and runs the detection and response technology behind a managed security service. The role deploys and tunes SIEM, EDR, and SOAR platforms, writes and refines detection rules aligned to MITRE ATT&CK, and automates response with KQL, PowerShell, and APIs to cut detection and response times. As a Tier 3 escalation point, the engineer leads complex investigations and forensic analysis, supports and trains SOC analysts, onboards customers, and maintains the documentation, dashboards, and reporting that support compliance with frameworks such as NIST and ISO 27001.
Roles and Responsibilities
SIEM and XDR Platform Ownership:
· Takes end-to-end ownership of the SIEM, EDR, and SOAR platforms that power the managed service, keeping them resilient, performant, and cost-effective as customer numbers and data volumes grow.
· Shapes how the wider security ecosystem fits together, bringing in third-party tools and threat intelligence where they add genuine detection value and retiring what no longer earns its place.
· Safeguards endpoint protection standards across the customer estate, balancing strong baseline policy with the flexibility customers need to operate their businesses.
Detection Engineering:
· Leads the evolution of the service’s detection capability, ensuring it can see and surface the threats that matter most to customers, with coverage mapped to MITRE ATT&CK.
· Champions detection quality, striking the right balance between coverage and noise so that analysts spend their time on genuine threats rather than false positives.
· Keeps detection strategy one step ahead of adversaries, translating emerging threats, threat intelligence, and lessons from real incidents into stronger defences.
Security Automation and Response:
· Drives the automation vision for the service, using KQL, PowerShell, and APIs to make detection and response faster, more consistent, and less reliant on manual effort.
· Acts as the guardian of safe automation, judging where automated action can be trusted to act alone and where human judgement must remain in the loop.
· Carries responsibility for measurable improvement in MTTD and MTTR, ensuring automation delivers real operational value for customers rather than complexity for its own sake.
Incident Response Leadership:
· Serves as the Tier 3 technical authority when incidents are complex or critical, providing calm, decisive leadership through containment, eradication, and recovery.
· Brings clarity in moments of uncertainty, establishing the true scope, severity, and root cause of incidents so that management and customers can make confident remediation decisions.
· Turns every significant incident into an opportunity to improve, protecting forensic integrity and making sure lessons learned strengthen detections and controls.
Customer Onboarding and Technical Advisory:
· Sets customers up for success from day one, acting as the design authority for their SIEM architecture, data sources, and detection baselines.
· Is a trusted technical adviser to customers, SOC analysts, and IT teams, bringing expert judgement to detection and response questions and helping to resolve differing views.
· Gives management a clear and honest view of risk, capability gaps, and resourcing needs, together with practical recommendations for addressing them.
Standards, Governance and Compliance:
· Ensures the service stands up to scrutiny, with platform configurations and detection content aligned to NIST, ISO 27001, and MITRE ATT&CK and a current view of coverage against each.
· Upholds internal policy, regulatory, and contractual obligations across all engineering work, raising concerns early wherever standards are at risk.
· Establishes the engineering disciplines, such as change control, version control, and documentation standards, that keep the service reliable and auditable.
Knowledge Leadership and Reporting:
· Acts as custodian of the service’s technical knowledge, ensuring platform configurations, detection logic, and operational processes are well understood and accessible to the team.
· Invests in the growth of analysts and junior engineers through mentoring and training, building a stronger and more capable SOC over time.
· Gives stakeholders a clear line of sight into detection performance, platform health, and compliance posture through meaningful dashboards and reporting.
Requirements:
Platform Expertise
· Deep expertise in Microsoft Security Stack: Sentinel, Defender for Endpoint, Defender for Cloud/Apps, Defender for Identity.
· Advantageous to have experience with other SIEM platforms (e.g., Splunk, QRadar, Elastic, ArcSight, LogRhythm).
Threat Detection & Incident Response
· Proficient in SIEM tuning, optimisation, threat detection, and use case development.
· Skilled in incident triage, investigation, and response workflows.
Security Automation & Scripting
· Experience in Logic Apps or equivalent automation workflows
· Strong scripting skills (KQL, PowerShell, Python) for automation and integration
· Leveraging API’s for custom SIEM integrations.
Security Frameworks & Best Practices
· Solid understanding of NIST, MITRE ATT&CK, ISO 27001, and cloud security best practices.
· Knowledgeable in security operations processes across hybrid and cloud environments.
Qualifications:
· A bachelor’s degree / diploma in a relevant area with a preference for Information Security, Computer Science or Computer Engineering.
Required
· Microsoft SC-200
· Microsoft SC-300
· Microsoft SC-400
· Microsoft AZ-500
· Linux LPIC-1
Recommended
· Microsoft SC-100
· Microsoft AZ-400
· Microsoft AZ-700
· Linux LPIC-2
· ISC2 CCSP
· ISACA CISA
· EC-Council CEH
- Department
- Cyber Security Operations Center (CyberSoc)
- Location
- Bryanston
- Remote status
- Hybrid
Bryanston
Let’s work together
Bring your talents, skills, and unique perspectives to a collaborative community of technology professionals. You’ll get the tools you need to do great work in a flexible environment. You’ll have time to learn new things. And you’ll be recognised and rewarded for your achievements.
About BUI
BUI is a global technology consultancy and managed services provider specialising in cloud, security, and networking solutions for mid-market and enterprise organisations.
Deeply rooted in the Microsoft ecosystem, we’re proud to be a Microsoft Azure Expert MSP and Microsoft Solutions Partner for the Microsoft Cloud, with proven expertise across Business Applications, Data & AI, Digital & App Innovation, Infrastructure, Modern Work, and Security.
With offices in East Africa, South Africa, the United Kingdom, the Republic of Ireland, and the United States, we help businesses become more productive, secure, and resilient every day.
At BUI, we believe in innovation, collaboration, and continuous learning. If you’re passionate about technology and eager to make an impact, we’d love to hear from you. Explore our open positions and discover where your next career move could take you.