At a Glance
- Tasks: Engineer and optimise Microsoft Sentinel for top-notch cyber security.
- Company: Join Asda, a leading retailer with a strong focus on innovation and collaboration.
- Benefits: Enjoy competitive salary, hybrid work, and fantastic perks like discounts and wellness services.
- Why this job: Make a real impact in cyber defence while working with cutting-edge technology.
- Qualifications: Experience with Microsoft Sentinel and strong problem-solving skills required.
- Other info: Flexible working options and a culture that celebrates diversity and inclusion.
The predicted salary is between 36000 - 60000 £ per year.
We are looking for a Cyber Security Specialist – SIEM Engineer to strengthen Asda’s detection and response capabilities. This is a hands-on engineering role, acting as a key enabler for the SOC and Incident Response Team (IRT), ensuring Asda gets maximum value from its investment in Microsoft Sentinel and the wider Defender XDR suite. The role will be responsible for onboarding and tuning log sources, building and optimising detections, and driving continuous improvement in SOC maturity.
Key Responsibilities
- Engineer, configure, and maintain Microsoft Sentinel as Asda’s SIEM, ensuring effective log ingestion, correlation, and alerting alongside existing Security Engineering function.
- Build, tune, and optimise detections, analytic rules, and automation (SOAR) to support SOC monitoring and IRT investigations.
- Integrate and enhance visibility across the Microsoft Defender XDR ecosystem, driving log source value and efficiency (Defender for Endpoint, Identity, Office 365, Cloud Apps, Entra ID).
- Onboard and manage diverse log sources (cloud, endpoint, network, SaaS, third party) to enrich SOC coverage.
- Support SOC analysts and incident responders with deep technical investigations and context enrichment.
- Develop dashboards, workbooks, and metrics to demonstrate SOC effectiveness and identify gaps.
- Partner with Threat Intelligence to translate IOCs/TTPs into actionable detections mapped to MITRE ATT&CK.
- Lead continuous improvement efforts to mature SIEM and SOC capabilities, reducing false positives and increasing detection fidelity.
- Maintain awareness of Microsoft’s evolving security capabilities; recommend and implement enhancements to strengthen resilience.
- Document engineering standards, playbooks, and knowledge articles for ongoing SOC/IRT operations.
Skills & Experience
- Strong hands-on experience with Microsoft Sentinel SIEM — log source integration, KQL queries, analytic rule development, automation.
- Familiarity with the Microsoft Defender XDR suite (Defender for Endpoint, Identity, O365, Cloud Apps).
- Understanding of SOC operations, incident response workflows, and detection engineering principles.
- Proficiency in Kusto Query Language (KQL) for writing detections and reports.
- Knowledge of logging, telemetry, and security data sources across cloud and on-premise environments.
- Experience building and maintaining SOAR playbooks (preferably Microsoft Logic Apps).
- Strong problem-solving and analytical skills; ability to identify gaps and implement solutions.
- Effective communicator; able to translate technical details into value for SOC and business stakeholders.
Desirable:
- Microsoft certifications (e.g., SC-200, SC-300, AZ-500, MS-500).
- Familiarity with automation and scripting (PowerShell, Python).
- Experience with threat hunting, purple teaming, or threat-informed defence.
- Exposure to large-scale retail or enterprise environments.
What Success Looks Like
- Sentinel SIEM is well-engineered, integrated, and delivering high-fidelity detections to SOC.
- SOC analysts and IRT can respond faster and with greater confidence thanks to improved visibility and automation.
- False positives are reduced; alerting is tuned and aligned to real-world threats.
- Coverage across Asda’s critical systems (cloud, endpoint, identity, email, SaaS) is comprehensive and monitored.
- Continuous improvement is evident — SOC maturity increases quarter by quarter.
What You’ll Gain
- Being a key engineer enabling Asda’s frontline cyber defence.
- Hands-on experience with Microsoft’s leading-edge security stack at enterprise scale.
- Opportunity to influence SOC/IRT strategy and tooling improvements.
- A collaborative, values-led culture with career growth opportunities.
- Hybrid working, competitive benefits, and the chance to protect a brand trusted by millions.
Asda Culture: How We Work
- One team: collaboration across SOC, IRT, Threat Intel, Risk, and wider Technology.
- Customer-first: protecting trust is central to everything we do.
- Innovative: continuously improving detections, automation, and resilience.
- Ethical: acting transparently and responsibly in all we deliver.
This role is open to job share / Part-time / Flexible working. Please be advised that this position requires attendance at Asda House in Leeds for a minimum of three days per week.
We’re really looking forward to having you around!
Everything you’ll love:
- Discretionary company bonus
- Company pension up to 7% matched
- Company Car allowance of £5,700
- 15% colleague discount in store and online
- Free access to wellbeing services such as Stream, 24/7 virtual GP, counselling, health and dental cash plans and a 24/7 employee assistance helpline, alongside discounts across a range of services and activities, from airport parking, enhanced to theme parks and cinemas.
- Asda Allies Inclusion Networks – helping colleagues to make sure everybody is included and that our differences are recognised and celebrated
- Excellent parental leave policies, including maternity & adoption leave, paternity leave, shared parental leave, neonatal care leave, and support for those doing fertility treatments.
We want all colleagues to be able to bring their best and true selves to work, every day. Simply put, we want our colleagues to be Proud to be Asda and proud to be themselves.
Cyber Security Specialist – SIEM Engineering in Leeds employer: Asda Stores Ltd
Contact Detail:
Asda Stores Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Specialist – SIEM Engineering in Leeds
✨Tip Number 1
Network like a pro! Reach out to current employees at Asda or in the cyber security field. A friendly chat can give you insider info and maybe even a referral, which can really boost your chances.
✨Tip Number 2
Prepare for the interview by brushing up on your KQL skills and understanding Microsoft Sentinel inside out. We want to see you shine with practical examples of how you've tackled similar challenges in the past.
✨Tip Number 3
Show off your passion for cyber security! Share your thoughts on the latest trends or challenges in the industry during interviews. It’ll demonstrate your enthusiasm and commitment to continuous improvement.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re serious about joining the Asda team.
We think you need these skills to ace Cyber Security Specialist – SIEM Engineering in Leeds
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cyber Security Specialist role. Highlight your hands-on experience with Microsoft Sentinel and any relevant projects you've worked on. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how you can contribute to our SOC and Incident Response Team. Keep it engaging and personal – we love to see your personality come through.
Showcase Your Skills: Don’t forget to showcase your technical skills, especially in KQL and automation. Mention any Microsoft certifications you have, as they can really set you apart. We’re keen on seeing how you can drive continuous improvement in our SOC capabilities!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us that you’re serious about joining our team at Asda!
How to prepare for a job interview at Asda Stores Ltd
✨Know Your SIEM Inside Out
Make sure you’re well-versed in Microsoft Sentinel and its features. Brush up on log source integration, KQL queries, and analytic rule development. Being able to discuss your hands-on experience confidently will show that you’re ready to hit the ground running.
✨Showcase Your Problem-Solving Skills
Prepare examples of how you've tackled challenges in previous roles, especially related to SOC operations or incident response workflows. Highlight specific instances where you identified gaps and implemented effective solutions, as this will demonstrate your analytical skills.
✨Communicate Clearly and Effectively
Practice explaining complex technical concepts in simple terms. You’ll need to translate technical details into value for both SOC and business stakeholders, so being an effective communicator is key. Consider role-playing with a friend to refine your delivery.
✨Stay Updated on Cyber Security Trends
Familiarise yourself with the latest developments in Microsoft’s security capabilities and broader cyber security trends. Showing that you’re proactive about continuous learning will impress interviewers and align with Asda's innovative culture.