Security Engineer (SIEM) in London

Security Engineer (SIEM) in London

London Temporary 67500 - 82500 £ / year (est.) Home office (partial)
I

At a Glance

  • Tasks: Design and implement security monitoring for a new secure cloud platform.
  • Company: Join a mission-driven team focused on high-assurance digital platforms.
  • Benefits: Hybrid working, competitive pay, and opportunities for professional growth.
  • Other info: Work in a dynamic environment with a focus on innovation and security.
  • Why this job: Make a real impact by enhancing security for critical public services.
  • Qualifications: Experience in SIEM solutions and strong collaboration skills required.

The predicted salary is between 67500 - 82500 £ per year.

Duration: 12+ Months

Start Date: ASAP

Clearance: Active SC-Clearance and willing to go through DV

This role is delivered within secure environments. Candidates must have an active Security Clearance (SC) and be willing to undergo Developed Vetting (DV).

Opening: Join the Mission. We design and deliver secure-by-default digital platforms for high-assurance environments. We’re currently building a new secure cloud platform based on Google Distributed Cloud (GDC) and are looking for a Security Engineer (SIEM) to lead the design and implementation of security monitoring and observability capabilities. This role offers the opportunity to build a SIEM capability from the ground up, influence security architecture decisions, and directly support SOC operations protecting critical public sector services.

About the Opportunity: As a Security Engineer (SIEM), you’ll be responsible for building and enhancing security monitoring and detection capabilities across complex environments. You will design and maintain SIEM use cases, onboard and normalise data sources, and continuously tune detections to improve threat visibility and response. Working closely with incident response and platform teams, you’ll turn security data into actionable insight-strengthening detection coverage, reducing noise, and advancing overall security maturity.

Role Purpose: As a Security Engineer, you will be responsible for designing, building, and operating the Security Information and Event Management (SIEM) and security observability stack for a new GDC-based platform. You will:

  • Define how security logs, metrics, alerts, and telemetry are collected, processed, retained, and visualised.
  • Establish a cloud-native SIEM tool and monitoring capability.
  • Integrate cloud-native monitoring with existing on-premise SOC tooling.
  • Enable SOC analysts by providing reliable, actionable security insights.
  • Work closely with cloud engineers, security architects, SOC teams, and external vendors to ensure the solution meets security, operational, and compliance requirements.

What You’ll Be Doing:

  • Work with security and solution architects to design the end-to-end SIEM architecture for a secure Google Distributed Cloud (GDC) environment.
  • Define log, event, and telemetry standards across platform, infrastructure, Kubernetes, and application layers.
  • Decide which data sources are monitored locally versus forwarded to an existing on-prem SIEM.

SIEM Implementation & Integration:

  • Deploy Elastic SIEM using standard or shared Kubernetes clusters where appropriate.
  • Configure secure log forwarding from GDC components to an on-prem SIEM over dedicated, encrypted network links.
  • Integrate cloud audit logs, Kubernetes logs, workload logs, and security tooling into Elastic and on-prem platforms.

Detection Engineering & SOC Enablement:

  • Implement detections-as-code, version controlled and automated through CI/CD pipelines.
  • Create and tune detection rules, alerts, and dashboards for SOC analysts.
  • Align detections with threat intelligence and playbooks (e.g., Mandiant-aligned SOC workflows).

Observability & Troubleshooting:

  • Support monitoring of logs, metrics, and security signals to aid both security response and operational debugging.
  • Enable Platform Admins and Application Operators to self-serve diagnostics while maintaining security boundaries.

Documentation & Guidance:

  • Produce clear guidance for:
    • Platform Administrators configuring SIEM integrations
    • Application teams onboarding workloads and logs
    • SOC analysts using dashboards, alerts, and queries
  • Contribute to runbooks, operational procedures, and incident response documentation.

Security & Compliance:

  • Ensure logging and monitoring meet UK Government and high-assurance security requirements.
  • Support audits, assurance activities, and continuous improvement of the monitoring posture.

What You’ll Bring:

  • Strong experience as a Security Engineer, Detection Engineer, or SIEM Engineer.
  • Hands-on experience designing or operating SIEM solutions in cloud or hybrid environments.
  • Practical knowledge of Elastic SIEM / Elastic Stack, including:
    • Indexing and ingest pipelines
    • Detection rules and alerts
    • Dashboards and visualisations
  • Experience working with Kubernetes environments and their logging/monitoring patterns.
  • Familiarity with secure log forwarding, encryption, and network-restricted environments.
  • Ability to work closely with SOC teams and translate security requirements into technical implementations.
  • Experience with Google Cloud Platform (GCP) or Google Distributed Cloud (GDC).
  • Understanding of cloud audit logs, identity logs, and platform-level telemetry.
  • Experience deploying tools through cloud marketplaces or CI/CD pipelines.

Ways of Working:

  • Comfortable working in high-assurance, regulated environments.
  • Strong documentation and communication skills.
  • Able to work independently and take ownership of complex security integrations.

Bonus Points For:

  • Existing UK Government Security Clearance (SC or above).
  • Hands-on experience with Elastic Cloud on Kubernetes (ECK).
  • Experience implementing detections as code using Git, CI/CD, and infrastructure-as-code.
  • Knowledge of threat frameworks.
  • Familiarity with UK Government security standards and assurance processes.

Clearance Requirements: This role requires either an existing SC clearance or SC to be passed before commencement, with a willingness to undergo DV.

Work Pattern & Contract Type: Hybrid working (on-site presence required when needed; typically, ~3 days per week). Contract: Temporary / Fixed-term contract.

Security Engineer (SIEM) in London employer: IO Associates

Join a leading engineering organisation that values innovation and excellence, offering a dynamic work culture where your contributions directly impact high-performance solutions in safety-critical environments. With a strong focus on employee growth, you will have the opportunity to mentor fellow engineers and shape technical direction while working in an Agile/SAFe environment. Located in the UK, this role provides a unique chance to be part of cutting-edge projects in defence, aerospace, and industrial technology, ensuring a rewarding and meaningful career path.

I

Contact Details:

IO Associates Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer (SIEM) in London

Get Engaged in Cybersecurity Communities

Dive into online forums or local meetups, like OWASP events or Cybersecurity conferences. These spaces are packed with pros who can share insights and might even know about temporary roles at places like IO Associates.

Showcase Your Skills Publicly

Link your GitHub or create a series of blogs sharing your knowledge on cybersecurity topics. It’s a great way to demonstrate your expertise and attract attention from hiring managers, especially when they see your passion in action.

Stay On Top of Temp Opportunities

Keep an eye on platforms that list temporary positions specifically in tech. Websites focusing on contract roles in cybersecurity can lead straight to employers like IO Associates.

Make Contact with Recruiters Specialising in Cybersecurity

Reach out to recruitment agencies that focus on cybersecurity roles. They often have insights into temporary roles before they’re advertised and can put your name forward to companies like IO Associates.

We think you need these skills to ace Security Engineer (SIEM) in London

Security Clearance (SC)
Developed Vetting (DV)
SIEM Design and Implementation
Security Monitoring
Elastic SIEM / Elastic Stack
Kubernetes Logging and Monitoring
Cloud-native SIEM Tools

Some tips for your application 🫡

Show Off Your Technical Skills:In cybersecurity, it's vital to highlight your skills with relevant tools and technologies. Make sure your CV showcases your experience with firewalls, intrusion detection systems, and any cybersecurity frameworks you've worked with. This gives IO Associates a clear view of your capabilities right off the bat.

Certifications Matter:If you’ve got any cybersecurity certifications, like CompTIA Security+ or CISSP, flaunt them! These not only validate your skills but also show that you’re committed to the field. Add a section to your CV specifically for this, because in a temporary role like this, those credentials can really set you apart.

Tailor Your Cover Letter to the Role:For a temporary position, we want to see your willingness to learn and adapt quickly. Make your cover letter specific to the role at IO Associates; mention why you’re excited about the opportunity and how it fits your career goals. A personal touch can make a big difference!

Don’t Forget the Soft Skills:In cybersecurity, technical skills are crucial, but so are soft skills like teamwork and communication. Make sure to weave examples of how you've collaborated with teams or communicated complex ideas into your application. This shows that you're not just a tech whizz but also a great team player, perfect for a temporary role at IO Associates.

How to prepare for a job interview at IO Associates

Brush Up on Technical Skills

Make sure you’re familiar with the latest cybersecurity tools and techniques, like firewalls, intrusion detection systems, and malware analysis. During the interview with IO Associates for the Security Engineer (SIEM), be prepared to discuss specific scenarios where you tackled security threats or vulnerabilities.

Show Your Problem-Solving Prowess

Cybersecurity is all about thinking on your feet. Expect technical questions that require you to demonstrate your problem-solving abilities. You might be presented with a mock security breach scenario, so practising your responses to potential threats can be a game changer!

Demonstrate Your Adaptability

As this is a temporary role, showing that you're adaptable and quick to learn is crucial. Talk about times you've picked up new skills or reacted to changing situations quickly. Employers want to know you can hit the ground running and keep things secure during your short stay at IO Associates.

Bring Relevant Certifications

If you have any relevant cybersecurity certifications, like CompTIA Security+ or CEH, be sure to mention them. This can really help you stand out during a temporary hiring process, as it showcases your commitment to the field and your readiness to take on the Security Engineer (SIEM) role at IO Associates.