Available for UK contract work

Jordan Millar

Lead Detection Engineer

Nine years across five security operations centres, from analyst on the queue to building and leading a SOC from an empty tenant. I design detection content that holds up in production — mapped to real coverage, tuned against real telemetry, and defensible when a client asks how you know.

Most of that work sits in the Microsoft stack: Sentinel, Defender XDR, KQL and Logic Apps, usually across multi-tenant environments where the same content has to work for a dozen different clients without becoming a dozen different forks.

Capabilities

What I'm brought in to do

Detection engineering

Building and maintaining detection content that fires on what matters and stays quiet the rest of the time. Coverage mapped honestly against MITRE ATT&CK rather than counted by rule volume, and content versioned so it can be reviewed like any other codebase.

KQL · Sigma · SPL · MITRE ATT&CK · Detection-as-code

SOC build and uplift

Standing up an operation from nothing, or fixing one that's drowning: log source onboarding, use case design, triage standards, escalation paths, and the analyst enablement that makes it repeatable rather than dependent on one person.

Greenfield SOC · Use case design · Analyst enablement

Multi-tenant delivery

Detection content that has to serve many clients at once. Central rule sets with per-tenant tuning, minimal targeted changes to vendor and Content Hub content so it stays upgradeable, and reporting that survives client scrutiny.

Multi-workspace Sentinel · Lighthouse · Client reporting

Automation and response

Removing the repetitive half of triage from the queue. Enrichment, containment and case handling wired together so analysts spend their time on the alerts that need judgement, and response time stops depending on who's on shift.

Logic Apps · SOAR playbooks · Enrichment pipelines
Experience

Nine years, five SOCs

2024 — 2026

Lead Detection Engineer

Blackford Technologies · Abu Dhabi, UAE

  • Built the SOC from the ground up — tooling, detection catalogue, playbooks and analyst team — serving regional enterprise and government clients.
  • Owned detection engineering across a multi-tenant Microsoft Sentinel estate, including log source onboarding, use case design and per-client tuning.
  • Delivered client-facing detection engagements, including a sovereign air-gapped platform with no vendor content available.
2022 — 2024

Detection Engineer

BestSecret

  • Detection engineering and threat detection across a Microsoft-first enterprise estate.
  • Developed and tuned Sentinel analytics rules, cutting false positive volume while extending ATT&CK coverage.
2020 — 2022

Senior Threat Analyst · Splunk Content Developer

Proficio

  • Three progressive roles across the detection and analysis function of a global MSSP.
  • Authored Splunk detection content deployed across a shared multi-tenant client base.
  • Led investigations and escalations as a senior analyst on a 24/7 operation.
2017 — 2020

Senior Threat Analyst

ReliaQuest

  • Promoted twice. Threat detection, investigation and response at enterprise scale.
  • Recipient of the ReliaQuest Excellence Award.
2015 — 2017

Security Analyst

Capgemini · United Kingdom

  • Where it started. Security monitoring and incident handling, progressing through two roles into analysis.
Selected projects

Work worth talking about

Sovereign · Air-gapped

Detection catalogue for an air-gapped Kubernetes platform

A government client running a sovereign container platform with no outbound connectivity and no vendor detection content to fall back on. I built the catalogue from the platform's own telemetry — 78 detections, written SIEM-agnostic so the same logic ships as Sigma, KQL, ELK, Wazuh or SPL — alongside a coverage dashboard and executive reporting so the client could see exactly what was and wasn't being watched.

Multi-tenant

Detection tuning across a managed service estate

Vendor and Content Hub rules arrive generic and noisy. My approach is minimal and targeted: change the clause actually causing the false positives, keep the rule upgradeable against upstream, and document the reasoning. Across a multi-tenant Sentinel estate that's the difference between a queue analysts trust and one they learn to ignore.

Greenfield build

A security operations centre from nothing

Joined to build a capability that didn't exist yet: selected the stack, defined the use cases, wrote the first detections, set triage and escalation standards, and hired and trained the analysts — while delivering against client SLAs with the operation still being assembled around them.

Credentials

Certifications and education

Certifications

  • CISSPIn progress
  • Microsoft SC-200 — Security Operations AnalystCertified
  • Blue Team Level 1 (BTL1)Certified
  • CompTIA PenTest+Certified
  • CompTIA CySA+Certified
  • CompTIA Security+Certified
  • Splunk — multiple credentialsCertified
  • Carbon Black Advanced AnalystCertified
  • Certified Jupyter Detection EngineerIn progress

Verified badges on Credly.

Education & practice

  • MSc Cybersecurity & Threat IntelligenceIn progress

Hands-on practice is public — labs and rankings on TryHackMe. I write up detection engineering topics on Medium.

Contact

Available for UK contract work

Lead and principal detection engineering, security consulting, SOC build and uplift. Inside IR35 or umbrella PAYE. Happy to talk through a problem before anyone talks about a rate.