5 дней назад
SIEM Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SIEM Security Engineer (Elasticsearch/Kafka): Building and operating BT’s strategic SIEM capabilities through security data ingestion, enrichment, detection use cases, and performance monitoring with an accent on Elasticsearch pipelines, threat intelligence, and network security telemetry. Focus on tuning complex detections, optimizing SIEM infrastructure, and supporting incident response across enterprise security environments.
Location: Hybrid, based in Birmingham with 3 days in the office
Company
is a UK communications group operating brands including BT, EE, Openreach, and Plusnet.
What you will do
- Design, develop, operate, and support BT’s strategic network SIEM.
- Configure Elasticsearch pipelines to ingest security data, primarily from Kafka, as well as from networking equipment, servers, firewalls, and security appliances.
- Enrich security data with threat intelligence feeds and contextual information.
- Design and implement SIEM solutions and security detection use cases with security analysts and architects.
- Tune, optimize, and retire detection use cases while monitoring SIEM infrastructure performance.
- Support security engineering projects and work with security operations and incident response systems.
Requirements
- Proven experience in SIEM detection engineering and security logging and monitoring.
- Experience with SIEM, NGFW, proxy, IAM, vulnerability management, access management, and enterprise security controls.
- Experience with detection tuning, log source onboarding, and normalization.
- Strong analytical and troubleshooting skills, including investigation of complex security events.
- Understanding of MITRE ATT&CK, modern cyber threats, and security operations.
- Bachelor’s or master’s degree in a related field and 5+ years of engineering experience delivering cybersecurity solutions.
Nice to have
- Experience with Elastic Stack and ELK.
- Knowledge of offensive testing frameworks, Linux, Windows, and network administration.
- Experience with cloud services, OpenStack, Kubernetes, Git, DevOps, Terraform, or Ansible.
- Cybersecurity qualifications and knowledge of the Telecoms Security Act and related regulatory frameworks.
Culture & Benefits
- 10% on-target annual bonus.
- Private GP access, paid carers leave, and enhanced maternity, paternity, and adoption leave.
- BT and EE product discounts.
- Pension scheme with 5% employee and 10% employer contributions.
- Holiday purchase scheme with additional healthcare, dental, and gym options.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
IT Security Analyst (Cybersecurity)
11 дней назад
24/7 SOC Analyst (Cybersecurity)
11 дней назад
Senior SOC Analyst (Cybersecurity)
9 дней назад
3rd Line Security Specialist - 24x7 Shift (Cybersecurity)
8 дней назад
SOC Analyst (Cybersecurity)
11 дней назад
Senior Incident Response Analyst (AI)
132 480 - 336 960$