> Markdown version of [/jobs/ext/3314200-siem-engineer](https://www.wearedevelopers.com/jobs/ext/3314200-siem-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SIEM Engineer - **Company:** Trust In Soda Ltd - **Location:** Hampshire, UK - **Salary:** £156,000.0 - £182,000.0 - **Contract:** Temporary contract - **Skills:** Microsoft Azure, Data Normalization, Logic Synthesis of Circuits, Intrusion Detection and Prevention, Network Monitoring, Performance Tuning, Kusto Query Language, Microsoft Power Automate, Software Troubleshooting, Git, SC Clearance, Cybercrime, Microsoft Sentinel - **Published:** September 3, 2026 - **Apply:** https://www.trustinsoda.com/jobs/siem-engineer-35132405#apply-job ## About the Role * Active SC Clearance (Essential) * Strong Microsoft Sentinel engineering, administration and optimisation experience * Log source onboarding, custom parsers and data normalisation * Advanced KQL development and optimisation * Analytic rule/detection logic design and tuning * Logic Apps, Playbooks and SOAR automation * Azure DevOps/Git CI/CD pipeline implementation * Strong grounding in security monitoring, incident response and threat hunting * Strong troubleshooting and root cause analysis skills Desirable * SANS SEC503 - Network Monitoring and Threat Detection Candidates must hold active, valid SC Clearance. ## Description Specialist SIEM Engineer needed to develop, optimise and automate SSE's Microsoft Sentinel platform, supporting security monitoring, detection engineering and Project Amur/ECAF compliance. Scope * Onboard and integrate log sources into Sentinel; build custom parsers and data transformations * Design and optimise KQL queries; build and tune analytic rules and detection logic * Develop Logic Apps/SOAR workflows to automate response * Implement CI/CD pipelines (Azure DevOps/Git) for SIEM content deployment * Automate deployment/config across environments; tune detections to reduce false positives