Elastic SME (SIEM)
Outside IR35 | Farnborough
Talent Locker are supporting a Defence and National Security consulting organisation and are recruiting for an experienced Elastic SIEM SME to support critical operational capability within a highly secure environment.
PLEASE NOTE – this role requires onsite delivery, and candidates must hold UK SC Clearance prior to appointment.
This contract sits within an operational security function where you will play a key role in shaping and enhancing how security data is collected, analysed and used to support mission outcomes. Working alongside engineering and operational teams, you’ll bring deep Elastic expertise to improve detection coverage, operational insight and response effectiveness.
You’ll focus on strengthening SIEM capability through the development and optimisation of detection logic, ensuring reliable log ingestion into Elasticsearch and creating dashboards that provide meaningful visibility for security operations. The role also involves hands‑on investigation of alerts, supporting triage activities, and continuously refining detections to reduce noise and improve accuracy (particularly within technically constrained environments).
Responsibilities
- Build and maintain detection rules within Elastic SIEM
- Oversee log ingestion, parsing and enrichments to ensure high quality data
- Develop and maintain Kibana dashboards to support operations
- Monitor and investigate SIEM alerts and support incident triage
- Improve detection fidelity by refining logic and reducing false positives
- Work with stakeholders to align capability with operational priorities
Experience needed
- Hands‑on experience with Elasticsearch, Kibana, Elastic SIEM, ELK, Elastic stack etc.
- Proven ability to work with log pipelines, data normalisations etc
- Experience writing detections using KQL, EQL or similar
- Demonstrable experience operating in restricted or secure environments
- Has a sound understanding of security operations
- Awareness and knowledge of adversary techniques and detection frameworks (including MITRE ATT&CK)
- Supporting automation with some scripting capability (e.g. python/ bash)
To find out more or to apply, please send your CV to emma@talentlocker.co.uk
#J-18808-Ljbffr
Contact Detail:
Talent Locker Ltd Recruiting Team