SIEM Application Engineer

Experis
Birmingham, United Kingdom
9 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Job location

Birmingham, United Kingdom

Tech stack

Elasticsearch
Kusto Query Language
Security Information and Event Management
Mitre Att&ck
Cybercrime
Kibana

Job description

  • Analyse alerts generated by Elastic Security and validate detection accuracy.
  • Tune and optimise existing Elastic SIEM detection rules to improve fidelity and reduce false positives.
  • Map detections to the MITRE ATT&CK framework and identify coverage gaps.
  • Produce clear detection reports, tuning documentation, and analysis summaries.
  • Collaborate with SOC analysts, incident responders, and security engineering teams.

Requirements

  • Hands-on experience with Elastic Security / Elastic SIEM, Kibana, and Elasticsearch queries (EQL/KQL).
  • Strong understanding of detection logic, alert tuning, and threat behaviours.
  • Familiarity with MITRE ATT&CK.
  • Strong written communication skills for reporting and documentation.

Nice to Have

  • Experience in SOC, detection engineering, or threat hunting.
  • Exposure to common log types (endpoint, network, cloud).
  • Security certifications (Elastic, Security+, CySA+, etc.).

Apply for this position