Engineer - Splunk in City of Westminster

Engineer - Splunk in City of Westminster

City of Westminster Full-Time 60000 - 75000 £ / year (est.) No working from home possible
NCC Group

At a Glance

  • Tasks: Design, build, and manage Splunk SOAR service with a focus on automation and security.
  • Company: Join a leading Cyber Services company in London with a collaborative culture.
  • Benefits: Flexible working, generous holiday allowance, and health benefits.
  • Other info: Opportunity for career growth and involvement in innovative security projects.
  • Why this job: Make a real impact in cybersecurity while developing your skills in a dynamic environment.
  • Qualifications: Experience in Splunk SOAR development and strong problem-solving skills required.

The predicted salary is between 60000 - 75000 £ per year.

We are seeking an experienced Splunk Engineer to help design, build, and manage our Splunk SOAR service, with a strong focus on automation, security response, and service maturity. This role will be responsible for developing, reviewing, testing, and deploying Splunk SOAR playbooks into production environments, ensuring they are secure, reliable, and aligned with security governance and operational needs. The role requires a technically strong Splunk engineer with experience in SOAR development, Splunk architecture, and security engineering best practices. You will work closely with SOC teams, security engineers, and customers, owning your own workload and providing high‑quality delivery in a customer‑facing environment. Experience with AI‑enabled SOC capabilities, AI security tools, or AI‑assisted development is a strong advantage as we continue to evolve our automation and detection capabilities.

Key Responsibilities

  • Own the build, operation, and continuous improvement of the Splunk SOAR service.
  • Design, develop, review, and maintain Splunk SOAR playbooks to support security detection, investigation, and response.
  • Translate security use cases, incidents, and operational requirements into effective automated workflows.
  • Test SOAR playbooks thoroughly and manage controlled deployment into production environments.
  • Ensure playbooks and integrations follow security engineering best practices and governance requirements.
  • Work closely with SOC analysts, security engineering teams, and stakeholders to optimise automation outcomes.
  • Perform playbook tuning, troubleshooting, and enhancements to improve reliability and response times.
  • Maintain clear technical documentation for playbooks, integrations, and processes.
  • Support live security operations where SOAR automation is involved.
  • Manage your own queue of work, prioritising tasks and communicating progress effectively.
  • Engage directly with customers, providing technical guidance, support, and assurance.

Skills, Knowledge & Expertise

  • Proven experience as a Splunk Engineer, Splunk SOAR Engineer, or similar security automation role.
  • Strong hands‑on experience developing and managing Splunk SOAR playbooks.
  • Solid understanding of Splunk platform architecture, including: Search heads, indexers, forwarders, data ingestion and performance considerations.
  • Strong experience using Splunk SPL (Search Processing Language).
  • Experience integrating Splunk SOAR with security tools such as SIEM, IAM, EDR, firewalls, and ticketing platforms.
  • Strong understanding of security engineering best practices, including incident response and automation safety.
  • Good understanding of security governance, policies, and control frameworks.
  • General understanding of software development practices, including version control systems (e.g. Git), code review and release controls, familiarity with CI/CD pipelines and deployment workflows.
  • Ability to work independently and take ownership of delivery and outcomes.

Desirable / Nice‑to‑Have Skills

  • Practical knowledge of Python, particularly for playbook actions, scripting, or custom integrations.
  • Experience working with AWS and/or Azure environments.
  • Understanding of cloud security principles and services.
  • Knowledge of security engineering controls, particularly identity and access management (IAM).
  • Experience working with APIs, webhooks, and automation integrations.
  • Familiarity with AI‑driven SOC capabilities, such as AI‑assisted alert triage or incident enrichment, use of AI within detection and response workflows, experience using AI security coding tools or AI‑assisted development tools.
  • Exposure to infrastructure automation or infrastructure‑as‑code concepts.
  • Experience supporting managed security services or customer‑facing security platforms.

Personal Attributes

  • Strong customer‑facing skills, able to communicate clearly and confidently with technical and non‑technical audiences.
  • Highly organised, with the ability to manage your own workload and priorities effectively.
  • Analytical and methodical approach to problem‑solving and automation design.
  • Proactive mindset with a focus on continuous improvement.
  • Comfortable operating in fast‑paced, security‑critical environments.
  • Collaborative team player with a strong sense of ownership and accountability.

Job Benefits

  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco‑friendly car scheme.
  • Cycle Scheme: Stay fit and healthy with our cycle‑to‑work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.

Engineer - Splunk in City of Westminster employer: NCC Group

Join our dynamic team in London as a Splunk Engineer, where you'll thrive in a collaborative work culture that prioritises innovation and continuous improvement. We offer flexible working options, generous holiday allowances, and comprehensive benefits, including financial security and community engagement opportunities, making us an excellent employer for those seeking meaningful and rewarding careers in cybersecurity.

NCC Group

Contact Details:

NCC Group Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Engineer - Splunk in City of Westminster

Tip Number 1

Network like a pro! Reach out to folks in the industry, especially those already working with Splunk or in cyber services. Attend meetups or webinars, and don’t be shy about asking for informational interviews. You never know who might have the inside scoop on job openings!

Tip Number 2

Show off your skills! Create a portfolio showcasing your Splunk SOAR playbooks and any automation projects you've worked on. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.

Tip Number 3

Prepare for interviews by brushing up on common technical questions related to Splunk and security engineering. Practice explaining your past projects and how they align with the role. Remember, confidence is key, so own your experience!

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search. So, get that application in and let’s get you on board!

We think you need these skills to ace Engineer - Splunk in City of Westminster

Splunk Engineering
Splunk SOAR Development
Security Automation
Splunk Architecture
Search Processing Language (SPL)
Integration with Security Tools
Incident Response Best Practices

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with Splunk SOAR and security engineering. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant projects!

Show Off Your Technical Skills:When detailing your experience, be specific about your hands-on work with Splunk playbooks and any automation tools you've used. We love seeing concrete examples of how you've tackled challenges in previous roles.

Keep It Clear and Concise:While we appreciate detail, make sure your application is easy to read. Use bullet points for key achievements and keep paragraphs short. This helps us quickly grasp your qualifications and experience.

Apply Through Our Website:We encourage you to submit your application directly through our website. It’s the best way to ensure it gets into the right hands and allows us to track your application efficiently. Plus, it shows you're keen to join our team!

How to prepare for a job interview at NCC Group

Know Your Splunk Inside Out

Make sure you brush up on your Splunk knowledge, especially around SOAR playbooks and architecture. Be ready to discuss your hands-on experience with Splunk SPL and how you've integrated it with other security tools. This will show that you're not just familiar with the platform but can also leverage it effectively.

Demonstrate Your Problem-Solving Skills

Prepare to share specific examples of how you've tackled challenges in previous roles, particularly in automation and security response. Think about times when you optimised workflows or improved reliability in a production environment. This will highlight your analytical approach and proactive mindset.

Engage with Real-World Scenarios

Be ready to discuss real-world security incidents and how you would respond using Splunk SOAR. This could involve translating security use cases into automated workflows. Practising these scenarios can help you articulate your thought process clearly during the interview.

Show Off Your Customer-Facing Skills

Since this role involves direct engagement with customers, prepare to demonstrate your communication skills. Think of examples where you've successfully communicated technical concepts to non-technical audiences. This will reassure them that you can provide the necessary support and guidance in a customer-facing environment.