Based
Inverness · UK-wide
Right to work
British citizen
Engagement
Permanent or contract
Notice
None — immediate

Jordan Millar

Lead Detection Engineer · SOC build-out & team lead

5 SOCs 4 countries 91% detection validity 0 days notice 00:00.09

I built a multi-tenant MSSP SOC from the ground up in a startup environment — operating model, processes, detection strategy — and led a team of five analysts running it, sustaining a 91% detection validity rate across client tenants.

Nine years across five SOCs, specialising in Microsoft Sentinel and Defender XDR detection engineering, detection-as-code and SOAR automation. Several of those years as a senior or lead analyst mentoring junior staff across both MSSP and internal environments, owning the interface between service provider and client.

Returning to the UK from the UAE. Seeking a Lead, Principal or SOC Management role, permanent or contract.

Capability

What I'm brought in to do

Detection engineering

Authoring, tuning and retiring KQL analytics mapped to MITRE ATT&CK, with coverage assessed honestly rather than counted by rule volume. Detections packaged as versioned YAML and deployed repeatably instead of hand-configured per environment.

KQL · Detection-as-code · Sigma & YARA · AttackIQ

SOC build-out and leadership

Defining the operating model, processes and detection strategy for an operation that doesn't exist yet — then managing the people who run it. Shift coverage, workload allocation, analyst development and the QA that keeps investigation quality consistent.

Operating model · Team of 5 · SOC QA/QC · Mentoring

Multi-tenant delivery

Detection content that has to serve many clients at once. Cross-tenant hunting through Azure Lighthouse and union / workspace() federation, targeted changes to Content Hub rules so they stay upgradeable, and reporting that survives client scrutiny.

Multi-workspace Sentinel · Lighthouse · Content Hub

Automation and response

Taking the repetitive half of triage off the queue. Azure Logic Apps playbooks for high-volume alert classes, Python tooling for enrichment and parsing, and SOPs spanning incident response, detection engineering and SOAR.

Logic Apps · Python · IR playbooks · Threat hunting
Experience

Five SOCs, four countries

Feb 2026
Aug 2026

Lead Detection Engineer / CSOC Analyst L3

Blackford Technologies · Abu Dhabi, UAE

  • Led the build-out of a multi-tenant MSSP SOC from the ground up, defining the operating model, processes and overall detection strategy.
  • Managed five SOC resources — shift coverage, holiday planning, workload allocation and the detection engineering pathway.
  • Sustained a 91% detection validity rate across the client estate through systematic tuning and rule lifecycle governance.
  • Owned the end-to-end detection lifecycle across client tenants, running detection-as-code and cross-tenant hunting via Azure Lighthouse.

Role ended by redundancy — the company ceased trading and closed its UAE office. Written confirmation available.

Sep 2024
Jan 2026

Senior SOC Analyst

BestSecret · Germany

  • Senior analyst in an internal Microsoft/Azure SOC, leading incident response from triage through containment to post-incident review.
  • Authored KQL detections and validated coverage through breach-and-attack simulation, closing gaps identified against ATT&CK.
  • Built Logic Apps playbooks that removed repetitive workload from the analyst queue, plus Python tooling for enrichment and parsing.
  • Led an exposure-management initiative and ran hypothesis-driven threat hunts feeding the detection backlog.
Jan 2020
Aug 2024

Senior Threat Analyst

Proficio · progressive roles

  • Senior SIEM/EDR incident response across Elastic, Splunk, ArcSight, CrowdStrike, Defender and Sentinel in a multi-client MSSP.
  • Built and owned the SOC quality assurance system, and designed the Skills Development Matrix for analyst progression.
  • As Splunk Content Developer, built custom detection use cases to client specification across authentication, ransomware and geolocation scenarios.

Senior Threat Analyst (Oct 2022) · Splunk Content Developer (Feb 2021) · Advanced Threat Analyst (Jan 2020)

Apr 2018
Dec 2019

Threat Analyst → Senior Threat Analyst

ReliaQuest · Dublin, Ireland

  • Advanced SIEM and EDR analysis across authentication attacks, ransomware, malware and phishing, using LogRhythm, Splunk, QRadar, Carbon Black and FireEye.
  • Promoted twice during tenure and awarded the ReliaQuest Excellence Award.
Aug 2015
Apr 2018

Security Analyst

Capgemini · United Kingdom

  • SIEM investigation using Huntsman, later QRadar and Splunk, and detection rule development within both platforms.
  • Engineering tasks including log backup, IDPS signature updates, health checks and reporting, with direct customer relationship management.

Security Analyst (Jul 2016) · Service Centre Analyst (Aug 2015)

Credentials

Certifications and education

Certifications

  • Microsoft SC-2002024
  • Blue Team Level 12022
  • CompTIA PenTest+2021
  • CompTIA CySA+2021
  • CompTIA Security+2019
  • Splunk Core Advanced Power User2021
  • Splunk Core Certified Power User2020
  • Carbon Black Advanced Analyst2019
  • CISSPIn progress

Verified badges on Credly.

Education

  • MSc Cybersecurity & Threat IntelligenceIn progress
  • Certified Junior Detection EngineerIn progress
  • HNC / NC Computing — UHI2012–14

MIA Digital University, dual degree with UDIMA Spain. CJDE with Security Blue Team. Deloitte Employability Award at North Highland College.

Outreach

Cyber careers talks in all-female schools with Junior Achievement Ireland, a return visit to North Highland College, and ReliaQuest's stall at Dublin Tech Summit.

Contact

Open to Lead, Principal and SOC Management roles

Permanent or contract, inside IR35 or PAYE, UK-wide — onsite, hybrid or remote. Available immediately with no notice period. Happy to talk through a problem before anyone talks about money.