11 дней назад
Cyber Operations Security Engineer (SIEM/Sentinel)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Operations Security Engineer (SIEM/Sentinel): Engineering and maintaining customer cyber security monitoring platforms with an accent on SIEM onboarding, data connectors, KQL, automation, dashboards, and reliable ingestion pipelines. Focus on tuning Sentinel, resolving parsing and transformation issues, monitoring data fidelity, and improving cyber operations services for customers.
Location: Hybrid in Manchester or Marlow, with 2 days in the office and 3 days working from home
Company
is a UK IT infrastructure provider delivering cyber security monitoring, analysis, assessment, and remediation services.
What you will do
- Deliver end-to-end SIEM and Microsoft Sentinel engineering, including customer onboarding, data connectors, integrations, KQL, automation, dashboards, and reporting.
- Configure, deploy, maintain, and optimise security monitoring and assessment platforms.
- Tune and enrich Sentinel while aligning it with other SIEM tools and security platforms.
- Maintain reliable SIEM ingestion pipelines by resolving connector, parsing, content, automation, and transformation issues.
- Monitor latency, throughput, and data fidelity to prevent data loss and improve service effectiveness.
- Work with customers and internal stakeholders to identify improvements and apply engineering best practices.
Requirements
- Knowledge of incident response frameworks such as NIST CSF, SOC 2, or equivalent.
- Understanding of information security architecture and policies related to logging, including secure transport, retention, and privacy by design.
- Strong written and verbal communication skills, including the ability to explain technical standards, runbooks, and feed specifications to non-technical audiences.
- Customer-focused and proactive approach to resolving technical issues.
- Experience in a managed service provider or MSSP environment is strongly preferred; similar experience outside a SOC may also be considered.
Nice to have
- Experience with AlienVault, Elastic, EDR/MDR tools, vulnerability management platforms, or other SIEM and information security management platforms.
Culture & Benefits
- Hybrid working with 2 office days and 3 home-working days each week.
- Flexible start and finish times.
- Flexibility around school drop-off and pick-up times.
- Supportive, collaborative, and inclusive working environment.
- Support and reasonable adjustments are available throughout the recruitment process for disability or neurodiversity.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Security Design & Implementation Specialist (Cybersecurity)
14 дней назад
Security Engineer (AI)
214 000 - 280 000$
14 дней назад
Senior Information Security Infrastructure Engineer (Security Architecture)
14 дней назад
Vulnerability Manager (Cybersecurity)
NDA
13 дней назад
Head of Information Security (Fintech)
11 дней назад