At a Glance
- Tasks: Design and deploy cutting-edge SIEM solutions for a new Security Operations Centre.
- Company: Join a leading global tech and cyber organisation with a focus on innovation.
- Benefits: Enjoy a 10% annual bonus, hybrid working, and an excellent benefits package.
- Other info: Great career progression opportunities in a dynamic and challenging environment.
- Why this job: Be part of building a significant cyber security programme from the ground up.
- Qualifications: Strong experience with SIEM platforms like Splunk and Microsoft Sentinel is essential.
The predicted salary is between 70000 - 90000 £ per year.
A leading global technology and cyber organisation is building a new Security Operations Centre to support the cyber defence of a major international defence programme. The environment will span Microsoft Cloud services and on-premises data centres across multiple regions and classification levels, creating a technically challenging and highly significant cyber security programme.
The SIEM Engineer will support the design, deployment, configuration and ongoing development of the SOC’s security monitoring capability. The role will work across technologies including Splunk, Microsoft Sentinel, SOAR, Microsoft XDR and wider security tooling, with a major focus on SIEM engineering, data onboarding, integrations, detection content and threat-led use cases.
What’s on offer
- 10% annual bonus
- Opportunity to help build a new enterprise-scale SOC from the ground up
- Hybrid working with customer-site attendance near Frimley approximately once every one to two weeks
- London and Frimley are ideal locations, with flexibility for candidates based elsewhere who can travel regularly
- Excellent benefits package
- Strong technical development and career progression opportunities
- Candidates must be eligible to obtain SC clearance
What you need
- Strong experience designing, building, deploying and operating SIEM and SOAR platforms
- Hands-on experience with Splunk and/or Microsoft Sentinel, ideally with strong exposure to both
- Experience with technologies such as Splunk Enterprise Security, Splunk SOAR, UBA, Elastic or Microsoft XDR
- Proven experience deploying and configuring SIEM platforms across cloud and/or on-premises environments
- Strong experience with log collection and onboarding data sources into a SIEM
- Ability to define and develop threat-led detection use cases, playbooks and automation content
- Experience integrating SIEM platforms with identity management, vulnerability management, asset management, threat intelligence and case management systems
- Strong knowledge of Azure and/or AWS security controls and detection capabilities
- Experience deploying security technologies across cloud, containerised and virtual machine environments
- Strong understanding of enterprise ICT and security architecture
- Good networking knowledge, including TCP/IP and the ability to identify normal and abnormal network traffic
- Detailed understanding of threat intelligence, threat actors and TTPs
- Experience developing technical test procedures against functional and non-functional requirements
- Strong technical documentation and client-facing communication skills
SIEM Engineer - Hybrid in Frimley employer: ANSON MCCADE
Anson McCade is an exceptional employer that prioritises employee well-being and professional growth, offering a flexible remote working environment in the UK. With a strong focus on security and digital transformation, employees benefit from comprehensive training programmes and clear pathways for career advancement, all while contributing to impactful projects alongside talented teams and senior stakeholders.