SIEM Engineer in London

SIEM Engineer in London

London Full-Time 60000 - 70000 ÂŁ / year (est.) No home office possible
Sopra Steria

At a Glance

  • Tasks: Lead the design and implementation of enterprise security monitoring platforms.
  • Company: Dynamic cybersecurity firm focused on innovation and collaboration.
  • Benefits: Competitive salary, car allowance, private healthcare, and generous leave options.
  • Other info: Join a diverse team committed to equality and professional growth.
  • Why this job: Make a real impact in cybersecurity while developing your skills in a supportive environment.
  • Qualifications: Experience with Splunk and SIEM engineering; strong problem-solving skills.

The predicted salary is between 60000 - 70000 ÂŁ per year.

We are looking for a Managing Security Engineer to lead the design, implementation and documentation of enterprise security monitoring platforms. This is a key technical leadership role, responsible for ensuring the right tooling, controls and processes are in place to help protect and monitor our clients’ environments. This opportunity is ideally suited to someone with strong hands‑on experience deploying and managing Splunk at enterprise scale. In return, the role offers the chance to broaden your capability and gain deeper experience in Elastic Security, with support to build your expertise further.

You will work closely with cross‑functional teams to assess risk, design effective security controls and define testing requirements. You will champion security by design, promote engineering excellence and act as a trusted advisor to clients, helping them understand their security challenges and implement practical, effective solutions to strengthen their security posture. This is an excellent opportunity to deepen your hands‑on cybersecurity expertise while making a meaningful impact across both client and organisational security. This role is permanent and requires full‑time, on‑site working in Hemel Hempstead. The successful candidate may also participate in an out‑of‑hours call‑out rota.

What you will be doing:

  • Lead the deployment, management and optimisation of Splunk Enterprise and Splunk ES platforms in large, complex environments.
  • Support and develop capability in Elastic Stack / Elastic Security, with training and upskilling provided as needed.
  • Design, implement and maintain data pipelines, including log ingestion, enrichment and schema standardisation.
  • Develop and tune security detection content, translating threat intelligence and TTPs aligned to MITRE ATT&CK into actionable, high‑value alerts.
  • Manage the full detection content lifecycle: design, test, deploy, monitor, tune and retire, using version control and rollback processes.
  • Automate workflows and platform configurations using CI/CD, SOAR, scripting and Infrastructure as Code tools such as Terraform and Ansible.
  • Ensure platform performance, stability and resilience through capacity planning, high availability, disaster recovery and proactive monitoring.
  • Provide technical leadership and guidance to internal teams and clients on security monitoring strategy and best practice.

What you will bring:

  • Proven experience deploying and managing Splunk at enterprise scale.
  • Strong hands‑on knowledge of SIEM engineering, including indexing, parsing, onboarding and performance tuning.
  • Experience designing and optimising detection content, including MITRE ATT&CK‑aligned use cases and alert tuning to reduce noise.
  • Good understanding of data pipeline engineering, log enrichment, data quality and large‑scale ingestion architectures.
  • Strong knowledge of SPL; experience with KQL and EQL would be beneficial, but is not essential.
  • Experience with automation and Infrastructure‑as‑Code within security monitoring or SIEM environments.
  • Solid understanding of SIEM platform operations, including clustering, scaling, high availability, disaster recovery and performance optimisation.
  • Strong problem‑solving skills and a proactive approach to improving security operations.
  • An interest in developing expertise in Elastic Security, with support and training available as part of the role.

Employment Type: Full Time, Permanent

Location: Hemel Hempstead

Security Clearance Level: DV Cleared

Salary: from ÂŁDOE

Benefits: ÂŁ5400 Car Allowance, 25 days annual leave with the option to buy additional days, private health care, life assurance, pension, and generous flexible benefits fund.

We embrace difference as a source of creativity, innovation and competitive advantage and are striving to become a more diverse organisation. We welcome applications from people with a diverse variety of backgrounds and identities. We are committed to equality of opportunity for all and do not discriminate on the basis of race, religion, colour, gender, age, disability, sexual orientation or marital status. We have partnered with Vercida, the UK's largest diversity and inclusion focused careers site, where all our vacancies are available in an accessible format. We participate in the Disability Confident scheme and are committed to offering an interview to any candidate with a disability, who meets the minimum criteria for the role. If you believe this could apply to you, please let us know when completing your application.

SIEM Engineer in London employer: Sopra Steria

Join a forward-thinking organisation in Hemel Hempstead as a SIEM Engineer, where you will lead the deployment and management of enterprise security monitoring platforms. We offer a supportive work culture that prioritises employee growth through training in Elastic Security, alongside competitive benefits such as a generous car allowance, private healthcare, and a commitment to diversity and inclusion. This role not only allows you to deepen your cybersecurity expertise but also empowers you to make a significant impact on our clients' security posture.
Sopra Steria

Contact Detail:

Sopra Steria Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land SIEM Engineer in London

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups or webinars, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those involving Splunk or SIEM engineering. This gives you a chance to demonstrate your hands-on experience and technical prowess to potential employers.

✨Tip Number 3

Prepare for interviews by brushing up on common SIEM scenarios and challenges. Be ready to discuss how you've tackled similar issues in the past, and don’t forget to highlight your problem-solving skills and proactive approach!

✨Tip Number 4

Apply through our website! We love seeing applications directly from candidates who are genuinely interested in joining us. Plus, it’s a great way to ensure your application gets the attention it deserves.

We think you need these skills to ace SIEM Engineer in London

Splunk Deployment and Management
SIEM Engineering
Detection Content Design and Optimisation
Data Pipeline Engineering
Log Enrichment
SPL (Search Processing Language)
Automation in Security Monitoring
Infrastructure as Code (Terraform, Ansible)
Performance Tuning
High Availability and Disaster Recovery
Proactive Problem-Solving
MITRE ATT&CK Framework Knowledge
Cross-Functional Team Collaboration
Technical Leadership

Some tips for your application 🫡

Tailor Your CV: Make sure your CV reflects the skills and experiences that match the SIEM Engineer role. Highlight your hands-on experience with Splunk and any relevant projects you've worked on. We want to see how you can bring value to our team!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background aligns with our needs. Don’t forget to mention your interest in Elastic Security and how you plan to grow with us.

Showcase Your Problem-Solving Skills: In your application, give examples of how you've tackled challenges in previous roles. We love candidates who can think critically and come up with innovative solutions, especially in security operations!

Apply Through Our Website: We encourage you to apply directly through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. We can’t wait to hear from you!

How to prepare for a job interview at Sopra Steria

✨Know Your Splunk Inside Out

Make sure you brush up on your Splunk knowledge before the interview. Be ready to discuss your hands-on experience with deploying and managing Splunk at an enterprise scale, as this is crucial for the role. Prepare specific examples of how you've optimised Splunk platforms in complex environments.

✨Understand SIEM Engineering Fundamentals

Familiarise yourself with key concepts in SIEM engineering, such as indexing, parsing, and performance tuning. Be prepared to explain how you've designed and optimised detection content, especially in relation to MITRE ATT&CK. This will show that you can translate threat intelligence into actionable alerts.

✨Showcase Your Automation Skills

Since automation is a big part of this role, be ready to discuss your experience with CI/CD, SOAR, and Infrastructure as Code tools like Terraform and Ansible. Share specific instances where you've automated workflows or platform configurations to improve efficiency.

✨Demonstrate Problem-Solving Abilities

Prepare to talk about challenges you've faced in security operations and how you've proactively addressed them. Highlight your problem-solving skills and any innovative solutions you've implemented to enhance security posture, as this will resonate well with the interviewers.

SIEM Engineer in London
Sopra Steria
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>