Security Consultant - SIEM Engineer
Role details
Job location
Tech stack
Job description
We are looking for a talented and enthusiastic individual with excellent technical and client-facing skills, to act as an SIEM Engineer who will support the design, configuration and maintenance of a wide range of security tools. This is mid level role and the individual will be expected to work across a variety of technologies such as Splunk and Sentinel SIEM, Nessus Vulnerability management, Microsoft XDR and other as appropriate.
The role will range from advising on design, deploying and configuring new solutions, assessing existing deployments and client capabilities to make improvements and improve overall maturity. This role is situated within our Defence Business unit and requires a minimum of SC clearance, ideally DV clearance. The position is expected to work from company offices in the UK with some time on client sites in UK and occasional travel to Europe and Asia.
- Design, deploy and configuration of SIEM applications (e.g. SPLUNK enterprise, enterprise security, Splunk SOAR and UBA, Microsoft Sentinnel, Elastic, Microsoft XDR and other) including:
- Specify infrastructure requirements (RAM, Disk, CPU, Network bandwidth) for SIEM applications
- Integration of SIEM application with identity management solutions.
- Integration of SIEM applications with Vulnerability Management, and Asset and Configuration Management systems to enrich efficacy of the solution.
- Integration of SIEM application with Cyber Threat Intelligence and Case Management solutions.
- Design, implement and manage log collection and onboarding activities to SIEM.
- Identify initial set of use cases & playbooks for detection and automation content and required development, deployment, testing and release.
- Support deployment of SIEM application to both cloud hosting and containers, and OnPrem hosted VM's and containers
- Oversee deployment / implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
- Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
- The role is a cyber technical specialist with deep knowledge of the Cyber Monitoring technologies and cyber threat tools, tactics, techniques and procedures.
- Develop test procedures to test solutions meet functional and non-functional requirements
- Generalist Technical SME to support deployment and configuration of various tools including Jira and Cribl
Requirements
Do you have experience in TCP/IP?, * Knowledge and experience of design, build, deployment and operation of SIEM/SOAR tools (Splunk and Sentinel at a minimum) and other appropriate tooling e.g. SOAR, Threat Intelligence, traffic analysis tools etc. to identify signs of an intrusion, and advise where new/improved tooling could enhance the SOC operation
- Experience deploying and configuring SIEM applications (e.g. SPLUNK and/ or MS Sentinnel) in a performant manner on cloud and / or OnPrem to support high data rates
- Proven delivery and experience leading conducting onboarding activities onto a SIEM
- Strong knowledge of how Azure and AWS security functions work as security controls as well as detection tools to protect large cloud estates; Produce content and playbooks on Sentinel and Splunk to detect security breaches and recognise the importance of threat led Use Cases.
- Deep knowledge and experience of Enterprise ICT.
- Working with a range of security tooling/technology.
- Strong understanding of security architecture, in particular networking.
- Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
- Understand TCP/IP component layers to identify normal and abnormal traffic.