Security Engineer (SIEM)

Security Engineer (SIEM)

Temporary 60000 - 80000 € / year (est.) Home office (partial)
I

At a Glance

  • Tasks: Design and implement security monitoring for a cutting-edge cloud platform.
  • Company: Join a mission-driven team focused on secure digital solutions.
  • Benefits: Competitive pay, hybrid work model, and opportunities for professional growth.
  • Other info: Work in a dynamic environment with strong career advancement potential.
  • Why this job: Make a real impact in securing critical public sector services.
  • Qualifications: Experience in security engineering and SIEM solutions required.

The predicted salary is between 60000 - 80000 € per year.

Duration: 12+ Months

Start Date: ASAP

Clearance: Active SC-Clearance and willing to go through DV

This role is delivered within secure environments. Candidates must have an active Security Clearance (SC) and be willing to undergo Developed Vetting (DV).

Join the Mission: We design and deliver secure-by-default digital platforms for high-assurance environments. We're currently building a new secure cloud platform based on Google Distributed Cloud (GDC) and are looking for a Security Engineer (SIEM) to lead the design and implementation of security monitoring and observability capabilities. This role offers the opportunity to build a SIEM capability from the ground up, influence security architecture decisions, and directly support SOC operations protecting critical public sector services.

About the Opportunity: As a Security Engineer (SIEM), you'll be responsible for building and enhancing security monitoring and detection capabilities across complex environments. You will design and maintain SIEM use cases, onboard and normalise data sources, and continuously tune detections to improve threat visibility and response. Working closely with incident response and platform teams, you'll turn security data into actionable insight-strengthening detection coverage, reducing noise, and advancing overall security maturity.

Role Purpose: As a Security Engineer, you will be responsible for designing, building, and operating the Security Information and Event Management (SIEM) and security observability stack for a new GDC-based platform. You will:

  • Define how security logs, metrics, alerts, and telemetry are collected, processed, retained, and visualised.
  • Establish a cloud-native SIEM tool and monitoring capability.
  • Integrate cloud-native monitoring with existing on-premise SOC tooling.
  • Enable SOC analysts by providing reliable, actionable security insights.
  • Work closely with cloud engineers, security architects, SOC teams, and external vendors to ensure the solution meets security, operational, and compliance requirements.

What You'll Be Doing:

  • Work with security and solution architects to design the end-to-end SIEM architecture for a secure Google Distributed Cloud (GDC) environment.
  • Define log, event, and telemetry standards across platform, infrastructure, Kubernetes, and application layers.
  • Decide which data sources are monitored locally versus forwarded to an existing on-prem SIEM.

SIEM Implementation & Integration:

  • Deploy Elastic SIEM using standard or shared Kubernetes clusters where appropriate.
  • Configure secure log forwarding from GDC components to an on-prem SIEM over dedicated, encrypted network links.
  • Integrate cloud audit logs, Kubernetes logs, workload logs, and security tooling into Elastic and on-prem platforms.

Detection Engineering & SOC Enablement:

  • Implement detection-as-code, version controlled and automated through CI/CD pipelines.
  • Create and tune detection rules, alerts, and dashboards for SOC analysts.
  • Align detections with threat intelligence and playbooks (e.g., Mandiant-aligned SOC workflows).

Observability & Troubleshooting:

  • Support monitoring of logs, metrics, and security signals to aid both security response and operational debugging.
  • Enable Platform Admins and Application Operators to self-serve diagnostics while maintaining security boundaries.

Documentation & Guidance:

  • Produce clear guidance for:
    • Platform Administrators configuring SIEM integrations
    • Application teams onboarding workloads and logs
    • SOC analysts using dashboards, alerts, and queries
  • Contribute to runbooks, operational procedures, and incident response documentation.

Security & Compliance:

  • Ensure logging and monitoring meet UK Government and high-assurance security requirements.
  • Support audits, assurance activities, and continuous improvement of the monitoring posture.

What You'll Bring:

  • Strong experience as a Security Engineer, Detection Engineer, or SIEM Engineer.
  • Hands-on experience designing or operating SIEM solutions in cloud or hybrid environments.
  • Practical knowledge of Elastic SIEM / Elastic Stack, including:
    • Indexing and ingest pipelines
    • Detection rules and alerts
    • Dashboards and visualisations
  • Experience working with Kubernetes environments and their logging/monitoring patterns.
  • Familiarity with secure log forwarding, encryption, and network-restricted environments.
  • Ability to work closely with SOC teams and translate security requirements into technical implementations.
  • Experience with Google Cloud Platform (GCP) or Google Distributed Cloud (GDC).
  • Understanding of cloud audit logs, identity logs, and platform-level telemetry.
  • Experience deploying tools through cloud marketplaces or CI/CD pipelines.

Ways of Working:

  • Comfortable working in high-assurance, regulated environments.
  • Strong documentation and communication skills.
  • Able to work independently and take ownership of complex security integrations.

Bonus Points For:

  • Existing UK Government Security Clearance (SC or above)
  • Hands-on experience with Elastic Cloud on Kubernetes (ECK)
  • Experience implementing detections as code using Git, CI/CD, and infrastructure-as-code
  • Knowledge of threat frameworks
  • Familiarity with UK Government security standards and assurance processes

Clearance Requirements: This role requires either an existing SC clearance or SC to be passed before commencement, with a willingness to undergo DV.

Work Pattern & Contract Type: Hybrid working (on-site presence required when needed; typically, ~3 days per week). Contract: Temporary / Fixed-term contract.

Security Engineer (SIEM) employer: IO Associates

Join a forward-thinking organisation that prioritises security and innovation in high-assurance environments. As a Security Engineer (SIEM), you'll benefit from a collaborative work culture that encourages professional growth and offers the chance to shape cutting-edge security solutions. With hybrid working arrangements and a commitment to employee development, this role provides a unique opportunity to make a meaningful impact while advancing your career in a secure and supportive setting.

I

Contact Detail:

IO Associates Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer (SIEM)

Tip Number 1

Network, network, network! Get out there and connect with people in the industry. Attend meetups, webinars, or even just chat with folks on LinkedIn. You never know who might have a lead on that perfect Security Engineer role.

Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your SIEM projects or any relevant work. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.

Tip Number 3

Prepare for interviews like a pro. Research common questions for Security Engineers and practice your responses. Be ready to discuss your experience with Elastic SIEM and how you've tackled challenges in previous roles.

Tip Number 4

Don’t forget to apply through our website! We’re always on the lookout for talented individuals like you. Plus, it’s a great way to ensure your application gets seen by the right people.

We think you need these skills to ace Security Engineer (SIEM)

Security Clearance (SC)
Developed Vetting (DV)
SIEM Design and Implementation
Elastic SIEM / Elastic Stack
Kubernetes Logging and Monitoring
Cloud-native SIEM Tools
Detection Engineering

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Security Engineer (SIEM) role. Highlight your experience with SIEM solutions, cloud environments, and any relevant security certifications. We want to see how your skills align with our mission!

Showcase Your Projects:If you've worked on any projects related to security monitoring or detection capabilities, be sure to include them! We love seeing practical examples of your work, especially if they relate to building SIEM capabilities or integrating security tools.

Be Clear and Concise:When writing your application, keep it clear and concise. Use bullet points where possible to make it easy for us to read through your experience and skills. Remember, we’re looking for specific qualifications that match the job description!

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about what we do at StudySmarter!

How to prepare for a job interview at IO Associates

Know Your SIEM Inside Out

Make sure you’re well-versed in the specifics of SIEM solutions, especially Elastic SIEM. Brush up on your knowledge of indexing, ingest pipelines, and detection rules. Being able to discuss these topics confidently will show that you’re ready to hit the ground running.

Demonstrate Your Cloud Savvy

Since this role involves working with Google Distributed Cloud, it’s crucial to highlight your experience with cloud environments. Be prepared to discuss how you've integrated security monitoring in cloud settings and any challenges you’ve faced along the way.

Showcase Your Collaboration Skills

This position requires close work with SOC teams and other stakeholders. Share examples of how you’ve successfully collaborated in past roles, particularly in translating security requirements into technical implementations. This will demonstrate your ability to work effectively in a team.

Prepare for Scenario-Based Questions

Expect questions that ask how you would handle specific security incidents or design challenges. Think through potential scenarios related to SIEM implementation and detection engineering, and be ready to articulate your thought process and decision-making.