Security Engineer SIEM - Hybrid
Anson McCade
London, UK
about 1 month ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£72,000.0 - £82,000.0
Working hours
Regular working hours
Job source
Tech stack
Amazon Web Services
Microsoft Azure
Cloud Computing
Cyber Security
Computer Networks
System Configuration
Identity and Access Management
Intrusion Detection and Prevention
Microsoft Software
Security Information and Event Management
TCP/IP
Virtual Machines
+7 more
Software Vulnerability Management
Computer Network Technologies
Data Ingestion
Cyber Threat Analysis
Microsoft Sentinel
Splunk
Security Orchestration, Automation & Response
Job description
The SIEM Engineer will support the design, deployment, configuration and ongoing development of the SOC’s security monitoring capability. The role will work across technologies including Splunk, Microsoft Sentinel, SOAR, Microsoft XDR and wider security tooling, with a major focus on SIEM engineering, data onboarding, integrations, detection content and threat-led use cases.
Requirements
- Strong experience designing, building, deploying and operating SIEM and SOAR platforms
- Hands-on experience with Splunk and/or Microsoft Sentinel, ideally with strong exposure to both
- Experience with technologies such as Splunk Enterprise Security, Splunk SOAR, UBA, Elastic or Microsoft XDR
- Proven experience deploying and configuring SIEM platforms across cloud and/or on-premises environments
- Experience supporting high-volume data ingestion environments
- Strong experience with log collection and onboarding data sources into a SIEM
- Ability to define and develop threat-led detection use cases, playbooks and automation content
- Experience integrating SIEM platforms with identity management, vulnerability management, asset management, threat intelligence and case management systems
- Strong knowledge of Azure and/or AWS security controls and detection capabilities
- Experience deploying security technologies across cloud, containerised and virtual machine environments
- Strong understanding of enterprise ICT and security architecture
- Good networking knowledge, including TCP/IP and the ability to identify normal and abnormal network traffic
- Detailed understanding of threat intelligence, threat actors and TTPs
- Experience developing technical test procedures against functional and non-functional requirements
- Strong technical documentation and client-facing communication skills
Benefits & conditions
- Salary: £72,000 - £82,000
- 10% annual bonus
- Opportunity to help build a new enterprise-scale SOC from the ground up
- Hybrid working with customer-site attendance near Frimley approximately once every one to two weeks
- London and Frimley are ideal locations, with flexibility for candidates based elsewhere who can travel regularly
- Excellent benefits package
- Strong technical development and career progression opportunities
- Candidates must be eligible to obtain SC clearance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.totaljobs.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
10 months ago