Security Engineer

Precise Placements
London, UK
13 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
£70,000.0 - £85,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Amazon Web Services Data Analysis Application Layers Microsoft Azure Software as a Service Cloud Computing CompTIA Security+ Cyber Security Data as a Services Information Leak Prevention
+29 more
Linux Disaster Recovery Infrastructure as a Service (IaaS) Intrusion Detection and Prevention JSON Python (Programming Language) Network Security Microsoft Software Open Source Intelligence Platform as a Service (PAAS) Parsing Windows PowerShell Remote Access Technology ArcSight SIEM Tool Security Information and Event Management Syslog Extensible Markup Language (XML) Azure Service Bus Scripting Google Cloud Mitre Att&ck QRadar Cyber Threat Analysis Information Technology Cybercrime Microsoft Sentinel Apache Kafka Splunk Data Pipelines

Job description

As a Security Engineer, you will focus on strengthening and optimising our Security Information and Event Management (SIEM) platform. You will be responsible for onboarding new log sources, improving data pipelines, developing advanced detection use cases, and supporting incident response activities.

This is an excellent opportunity for a security professional who enjoys building scalable, high-performing security monitoring environments and working in a collaborative, fast-paced setting.

You will report to the Information Security Operations Manager and work closely with the wider security team and internal stakeholders to improve the organisation’s overall security posture., SIEM Engineering & Optimisation

  • Enhance and optimise the SIEM platform to improve performance, coverage, and detection accuracy
  • Assess SIEM architecture and recommend improvements across ingestion, parsing, correlation, and storage
  • Implement automation and orchestration (SOAR) to streamline security operations

Log Source Onboarding & Integration

  • Identify and onboard log sources across cloud, network, endpoint, identity, and application layers
  • Develop custom parsers, connectors, and ingestion workflows
  • Collaborate with internal teams and vendors to ensure high-quality telemetry

Detection Engineering

  • Design and implement detection use cases aligned to frameworks such as MITRE ATT&CK
  • Build and tune correlation rules, alerts, dashboards, and anomaly detections
  • Continuously improve detection quality and reduce false positives

SOC & Incident Response Support

  • Partner with SOC analysts to refine detection logic
  • Support investigations through advanced SIEM querying and data analysis
  • Provide subject matter expertise during complex security incidents

Documentation & Governance

  • Maintain clear documentation of SIEM architecture, data models, and detection logic
  • Ensure alignment with internal policies, compliance requirements, and industry standards

Requirements

Technical Expertise

  • Strong hands-on experience with SIEM platforms (e.g. Splunk, Microsoft Sentinel, QRadar, Elastic, LogRhythm, ArcSight, Exabeam)
  • Knowledge of log formats (JSON, syslog, XML, CEF) and ingestion methods (APIs, agents, Kafka, Event Hubs)
  • Experience in detection engineering, threat modelling, and attacker behaviour analysis
  • Familiarity with SOAR tools and automation workflows

Security Knowledge

  • Understanding of networks, Windows/Linux systems, cloud platforms (Azure, AWS, GCP), identity systems, and endpoint security tools
  • Knowledge of frameworks such as MITRE ATT&CK and threat hunting methodologies, * Degree (or equivalent experience) in a computing or related discipline
  • Proven experience across IT infrastructure and information security
  • Relevant certifications (e.g. GIAC, CISSP, SSCP, Microsoft SC-200/SC-100, CompTIA Security certifications)
  • Strong scripting skills (Python, PowerShell, or similar)
  • Excellent communication skills with the ability to engage stakeholders at all levels
  • Proactive, self-starting approach with strong problem-solving ability

Desirable Experience

  • Data Loss Prevention (DLP)
  • Network security and secure remote access solutions
  • Cloud and software-defined environments (SaaS, IaaS, PaaS, DaaS)
  • Cyber threat intelligence and open-source intelligence tools
  • Disaster recovery and business continuity planning
  • Knowledge of data privacy regulations

Additional Information

  • Some out-of-hours work may be required for planned changes or security incidents
  • Opportunity to contribute to strategic security initiatives and service improvements

If you are a motivated Security Engineer looking to make a tangible impact within a global, highly regulated environment, we would love to hear from you. Skills

  • SIEM and Security Operations
  • SIEM Implementation & Management
  • SIEM Platforms

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.reed.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

Videos

See all

Related articles

See all