- Based
- Inverness · UK-wide
- Right to work
- British citizen
- Engagement
- Permanent or contract
- Notice
- None — immediate
Jordan Millar
Lead Detection Engineer · SOC build-out & team lead
KQLcareer.kusto
// nine years, condensed
Career
| where Discipline in ("Detection Engineering", "SOC Leadership")
| where TimeGenerated > ago(9y)
| summarize SOCs = dcount(Organisation), Countries = dcount(Country)
| extend DetectionValidity = "91%", Notice = "none"
5 SOCs
4 countries
91% detection validity
0 days notice
00:00.09
I built a multi-tenant MSSP SOC from the ground up in a startup environment — operating model, processes, detection strategy — and led a team of five analysts running it, sustaining a 91% detection validity rate across client tenants.
Nine years across five SOCs, specialising in Microsoft Sentinel and Defender XDR detection engineering, detection-as-code and SOAR automation. Several of those years as a senior or lead analyst mentoring junior staff across both MSSP and internal environments, owning the interface between service provider and client.
Returning to the UK from the UAE. Seeking a Lead, Principal or SOC Management role, permanent or contract.
Capability
What I'm brought in to do
Detection engineering
Authoring, tuning and retiring KQL analytics mapped to MITRE ATT&CK, with coverage assessed honestly rather than counted by rule volume. Detections packaged as versioned YAML and deployed repeatably instead of hand-configured per environment.
KQL · Detection-as-code · Sigma & YARA · AttackIQ
SOC build-out and leadership
Defining the operating model, processes and detection strategy for an operation that doesn't exist yet — then managing the people who run it. Shift coverage, workload allocation, analyst development and the QA that keeps investigation quality consistent.
Operating model · Team of 5 · SOC QA/QC · Mentoring
Multi-tenant delivery
Detection content that has to serve many clients at once. Cross-tenant hunting through Azure Lighthouse and union / workspace() federation, targeted changes to Content Hub rules so they stay upgradeable, and reporting that survives client scrutiny.
Multi-workspace Sentinel · Lighthouse · Content Hub
Automation and response
Taking the repetitive half of triage off the queue. Azure Logic Apps playbooks for high-volume alert classes, Python tooling for enrichment and parsing, and SOPs spanning incident response, detection engineering and SOAR.
Logic Apps · Python · IR playbooks · Threat hunting
Experience
Five SOCs, four countries
Feb 2026
Aug 2026
Lead Detection Engineer / CSOC Analyst L3
Blackford Technologies · Abu Dhabi, UAE
- Led the build-out of a multi-tenant MSSP SOC from the ground up, defining the operating model, processes and overall detection strategy.
- Managed five SOC resources — shift coverage, holiday planning, workload allocation and the detection engineering pathway.
- Sustained a 91% detection validity rate across the client estate through systematic tuning and rule lifecycle governance.
- Owned the end-to-end detection lifecycle across client tenants, running detection-as-code and cross-tenant hunting via Azure Lighthouse.
Role ended by redundancy — the company ceased trading and closed its UAE office. Written confirmation available.
Sep 2024
Jan 2026
Senior SOC Analyst
BestSecret · Germany
- Senior analyst in an internal Microsoft/Azure SOC, leading incident response from triage through containment to post-incident review.
- Authored KQL detections and validated coverage through breach-and-attack simulation, closing gaps identified against ATT&CK.
- Built Logic Apps playbooks that removed repetitive workload from the analyst queue, plus Python tooling for enrichment and parsing.
- Led an exposure-management initiative and ran hypothesis-driven threat hunts feeding the detection backlog.
Jan 2020
Aug 2024
Senior Threat Analyst
Proficio · progressive roles
- Senior SIEM/EDR incident response across Elastic, Splunk, ArcSight, CrowdStrike, Defender and Sentinel in a multi-client MSSP.
- Built and owned the SOC quality assurance system, and designed the Skills Development Matrix for analyst progression.
- As Splunk Content Developer, built custom detection use cases to client specification across authentication, ransomware and geolocation scenarios.
Senior Threat Analyst (Oct 2022) · Splunk Content Developer (Feb 2021) · Advanced Threat Analyst (Jan 2020)
Apr 2018
Dec 2019
Threat Analyst → Senior Threat Analyst
ReliaQuest · Dublin, Ireland
- Advanced SIEM and EDR analysis across authentication attacks, ransomware, malware and phishing, using LogRhythm, Splunk, QRadar, Carbon Black and FireEye.
- Promoted twice during tenure and awarded the ReliaQuest Excellence Award.
Aug 2015
Apr 2018
Security Analyst
Capgemini · United Kingdom
- SIEM investigation using Huntsman, later QRadar and Splunk, and detection rule development within both platforms.
- Engineering tasks including log backup, IDPS signature updates, health checks and reporting, with direct customer relationship management.
Security Analyst (Jul 2016) · Service Centre Analyst (Aug 2015)
Credentials
Certifications and education
Certifications
- Microsoft SC-2002024
- Blue Team Level 12022
- CompTIA PenTest+2021
- CompTIA CySA+2021
- CompTIA Security+2019
- Splunk Core Advanced Power User2021
- Splunk Core Certified Power User2020
- Carbon Black Advanced Analyst2019
- CISSPIn progress
Verified badges on Credly.
Education
- MSc Cybersecurity & Threat IntelligenceIn progress
- Certified Junior Detection EngineerIn progress
- HNC / NC Computing — UHI2012–14
MIA Digital University, dual degree with UDIMA Spain. CJDE with Security Blue Team. Deloitte Employability Award at North Highland College.
Outreach
Cyber careers talks in all-female schools with Junior Achievement Ireland, a return visit to North Highland College, and ReliaQuest's stall at Dublin Tech Summit.