> Markdown version of [/jobs/ext/2174762-siem-engineer](https://www.wearedevelopers.com/jobs/ext/2174762-siem-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SIEM Engineer - **Company:** Iomart Limited - **Location:** UK (Remote available) - **Salary:** £49,598.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Microsoft Azure, Cyber Security, Data Integration, Intrusion Detection and Prevention, Python (Programming Language), Microsoft Security Essentials, Open Source Technology, Windows PowerShell, Software Tools, Kusto Query Language, Security Information and Event Management, Microsoft Power Automate, Delivery Pipeline, Malware, Cyber Threat Analysis, Infrastructure as Code (IaC), Infrastructure Automation Frameworks, Cybercrime, Bicep, Microsoft Sentinel, Purple Team (Cyber Security), Terraform, Serverless Computing - **Published:** August 22, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5852696957 ## About the Role * Have hands-on experience with Microsoft Sentinel, Microsoft Defender, or similar SIEM/SOC technologies. * Are passionate about cyber security and keeping up with emerging threats and attack techniques. * Have experience with KQL, PowerShell, Python, or other scripting and automation tools. * Enjoy solving complex technical challenges and improving processes through automation. * Can communicate confidently with both technical and non-technical audiences. * Thrive in collaborative environments and enjoy working with customers and colleagues. * Have an interest in detection engineering, threat hunting, security monitoring, and incident response. * Take ownership of your work, manage priorities effectively, and adapt in a fast-paced environment. * Are committed to continuous learning, professional development, and knowledge sharing. * Have experience using AI tools such as Microsoft Copilot to enhance productivity and streamline workflows. * Hold Microsoft security certifications such as SC-200, AZ-500, or SC-300. Bonus Points If You: * Have experience with Azure Logic Apps, Azure Functions, Terraform, Bicep, or Infrastructure as Code (IaC). * Have worked within a SOC, MSSP, or Managed Security Services environment. * Have experience with Detection-as-Code or Content-as-Code practices. * Have exposure to threat intelligence, threat hunting, malware analysis, or purple team activities. * Have integrated third-party security products and data sources into Microsoft Sentinel. * Have implemented AI capabilities, such as Copilot, within automations, workflows, or internal tooling. * Contribute to security tooling, open-source projects, technical content, or security research. ## Description As a SIEM Engineer at Atech, you will play a key role in designing, implementing, and optimising security monitoring solutions across a diverse range of customer environments. Working primarily with Microsoft Sentinel, Microsoft Defender, and the wider Microsoft Security ecosystem, you will help onboard customers into our Managed SOC service while supporting them in strengthening and maturing their overall security posture. This role combines technical engineering, detection development, automation, and customer engagement. You will be responsible for building and maintaining high-quality detections, configuring data integrations, tuning alerting, and developing automations that improve both the effectiveness and efficiency of our Security Operations Centre (SOC). You will work closely with SOC Analysts, Security Consultants, Engineers, and customers to deliver innovative security solutions that help organisations identify, investigate, and respond to threats more effectively. As part of a growing security practice, you will have the opportunity to shape the future of Atech's security services by contributing to detection engineering, automation initiatives, internal tooling, and service improvements. This is an excellent opportunity for someone who is passionate about cyber security, enjoys solving complex technical challenges, and wants to work with cutting-edge Microsoft security technologies., * Design, implement, and maintain detections, analytics rules, workbooks, watchlists, and automations within Microsoft Sentinel. * Onboard new customers into Atech's Managed SOC service, including configuring integrations, data connectors, and monitoring capabilities. * Optimise and tune alerts to improve detection quality, reduce false positives, and enhance analyst efficiency. * Develop and maintain security monitoring content aligned to customer requirements and emerging threats. * Design and implement automation solutions using Microsoft Sentinel, Logic Apps, PowerShell, Python, and other supporting technologies. * Identify opportunities to improve and streamline security operations through automation and process improvement. * Support incident detection and response activities through the development of tooling, workflows, and detection capabilities. * Develop and maintain internal security tooling, scripts, and deployment pipelines. * Work collaboratively with SOC Analysts and Engineers to continuously improve security monitoring and operational effectiveness. * Contribute to technical designs, peer reviews, and security-focused projects across the wider business. * Create and maintain clear technical documentation, standards, processes, and procedures. * Produce technical reports, dashboards, and service summaries for customers and internal stakeholders. * Assist customers and colleagues in understanding and adopting Microsoft security technologies and best practices. * Stay current with emerging cyber threats, attack techniques, and advancements within the Microsoft Security ecosystem. * Participate in training, certifications, and continuous professional development to support your career growth and ensure Atech remains at the forefront of security detection and response. ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)