At a Glance
- Tasks: Lead the design and implementation of security monitoring platforms to protect clients.
- Company: Join Sopra Steria, a leader in digital solutions for National Security.
- Benefits: Enjoy a competitive salary, car allowance, private healthcare, and generous leave options.
- Why this job: Make a real impact on cybersecurity while developing your expertise in a supportive environment.
- Qualifications: Experience with Elastic Security, Splunk, and strong problem-solving skills required.
- Other info: Flexible working arrangements available; we value your work-life balance.
The predicted salary is between 65000 - 91000 £ per year.
We are looking for a Managing Security Engineer (SIEM), you will lead the design, implementation and documentation of security monitoring platforms. You will ensure the right tooling is in place to protect and monitor our clients, working closely with cross-functional teams to assess risk, design security controls and define testing requirements. You will be a key technical leader, championing security by design and fostering a strong culture of security and engineering excellence across Sopra Steria. Acting as a trusted advisor, you will help clients understand their security challenges and lead the planning and implementation of effective controls to strengthen their security posture. This role offers an excellent opportunity to deepen your hands-on cybersecurity expertise while making a meaningful impact on both client and organisational security. This role is permanent and requires full time, on-site working in Hemel Hempstead. This role will also potentially be partaking in an out of hours call-out rota.
What you will be doing:
- Deploy, manage and optimise Elastic Stack (Elastic Security) and Splunk (Enterprise & ES) platforms at scale.
- Design, implement and maintain data pipelines, including log ingestion, enrichment and schema standardisation (ECS/CIM).
- Develop and tune security detection rules, translating threat intel and TTPs (MITRE ATT&CK) into actionable, low-noise alerts.
- Manage the full content lifecycle: design → test → deploy → monitor → tune → retire, with version control and rollback.
- Automate workflows and configurations using CI/CD, SOAR, scripting and IaC tools (Terraform, Ansible).
- Ensure platform performance, stability and reliability, including capacity planning, high availability, disaster recovery and proactive monitoring.
What you will bring:
- Hands-on experience with Elastic Security and Splunk ES, including detection engineering, indexing, parsing and performance tuning.
- Strong expertise in data pipeline engineering, log enrichment, data quality and large-scale ingestion architectures (ECS/CIM).
- Proven ability to design, test and optimise detection content, including MITRE ATT&CK-aligned rules and risk-based alerting (RBA).
- Advanced knowledge of SPL, KQL and EQL, focused on detection quality and noise reduction.
- Experience with automation and Infrastructure-as-Code in SIEM environments.
- Deep understanding of SIEM platform operations, including clustering, high availability, disaster recovery, scaling and performance optimisation.
- Strong problem-solving skills with a proactive approach to improving security operations.
If you are interested in this role but not sure if your skills and experience are exactly what we’re looking for, please do apply, we’d love to hear from you! Although this role is advertised as full-time, we support different ways of working and can offer a range of flexible working arrangements. So, if you’re interested and need to work flexibly, we encourage you to apply and talk to us about what might be possible.
Employment Type | Location | Security Clearance | Salary | Benefits
- Full Time, Permanent
- Hemel Hempstead ON-SITE
- DV Cleared
- Salary: from £65k+ depending on experience and developmental needs
- Benefits: Car Allowance, 25 days annual leave with the option to buy additional days, private health care, life assurance, pension, generous flexible benefits fund (3% of base salary).
Sopra Steria’s Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client’s goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK’s most complex safety-and-security-critical markets.
SIEM Engineer in Kings Langley employer: Sopra Steria Ltd
Contact Detail:
Sopra Steria Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land SIEM Engineer in Kings Langley
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the cybersecurity field. Attend meetups, webinars, or even local events. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, especially those related to Elastic Security and Splunk. This will give potential employers a taste of what you can do and set you apart from the crowd.
✨Tip Number 3
Don’t just apply blindly! Tailor your approach for each role. Research the company, understand their security challenges, and be ready to discuss how your experience aligns with their needs during interviews.
✨Tip Number 4
Apply through our website! We love seeing applications directly from candidates who are genuinely interested in joining us. Plus, it gives you a better chance to stand out and show your enthusiasm for the role.
We think you need these skills to ace SIEM Engineer in Kings Langley
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the SIEM Engineer role. Highlight your hands-on experience with Elastic Security and Splunk, and don’t forget to showcase your skills in data pipeline engineering and detection content optimisation.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about cybersecurity and how your experience aligns with our mission at StudySmarter. Be sure to mention any relevant projects or achievements that demonstrate your expertise.
Showcase Your Problem-Solving Skills: In your application, give examples of how you've tackled complex security challenges in the past. We love candidates who can think on their feet and come up with innovative solutions, so don’t hold back!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates. Plus, we’d love to hear from you!
How to prepare for a job interview at Sopra Steria Ltd
✨Know Your Tools Inside Out
Make sure you’re well-versed in Elastic Security and Splunk ES. Brush up on your detection engineering skills, indexing, and performance tuning. Being able to discuss specific examples of how you've deployed or optimised these platforms will show you're the right fit for the role.
✨Demonstrate Your Problem-Solving Skills
Prepare to share real-life scenarios where you've tackled security challenges. Highlight your proactive approach to improving security operations and how you've implemented effective controls. This will showcase your ability to think critically and act decisively under pressure.
✨Familiarise Yourself with MITRE ATT&CK
Since the role involves translating threat intel into actionable alerts, make sure you understand the MITRE ATT&CK framework. Be ready to discuss how you've designed and optimised detection content aligned with this framework, as it’s crucial for the position.
✨Show Your Collaborative Spirit
This role requires working closely with cross-functional teams, so be prepared to talk about your experience in collaboration. Share examples of how you've worked with others to assess risk and design security controls, emphasising your ability to foster a strong culture of security and engineering excellence.