Назад
Company hidden
4 дня назад

Senior Security Engineer - Monitoring & Detection (Splunk)

55 000 - 85 000GBP
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer - Monitoring & Detection (Splunk): Building and tuning detection logic and log-ingestion pipelines for secure UK government digital services with an accent on SIEM operations, cloud security, and data normalisation. Focus on validating high-fidelity alerts, optimising Cribl-based streaming and storage, mapping detections to MITRE ATT&CK, and translating technical risk for government stakeholders.

Location: Any UK office hub: Bristol, London, Manchester, or Swansea; part-time remote working is available. Occasional work outside standard Monday-to-Friday hours may be required during release and maintenance windows or to align with client operating hours.

Salary: £55,000–£85,000 per year

Company

hirify.global helps UK public sector organisations build and run secure, trustworthy, and resilient digital services.

What you will do

  • Build and tune detection rules across Splunk SPL, YARA, and EDR platforms.
  • Map detections to MITRE ATT&CK, monitor signal quality, and reduce false positives.
  • Validate rules through replay, load testing, and red-team scenarios while collaborating with L1–L3 analysts.
  • Manage Cribl log ingestion, including routing, filtering, normalisation, enrichment, deduplication, and NetFlow summarisation.
  • Manage streaming and storage across Kinesis, S3, and Amazon Security Lake, applying OCSF, data tiering, encryption, and least-privilege access.
  • Translate technical risk for government stakeholders and system owners while mentoring junior and mid-level engineers.

Requirements

  • Senior-level, hands-on security engineering experience across detection engineering, SIEM, log ingestion, or cloud security.
  • Experience with AWS, Azure, or GCP cloud security.
  • Advanced Splunk SPL, YARA, and EDR detection logic, or experience with Cribl, Kinesis, S3, Amazon Security Lake, and OCSF data normalisation.
  • Strong understanding of Zero Trust, identity-first security, secrets management, and network segmentation.
  • Experience working with or alongside UK Government or public sector stakeholders.
  • Eligibility for SC clearance requires five years of UK residency and a five-year employment history, or records back to full-time education.

Culture & Benefits

  • 30 days of paid annual leave.
  • Flexible working hours and part-time remote working.
  • Flexible parental leave.
  • Flexible benefits platform with Smart Tech, Cycle to Work, healthcare cash plan, and pension options.
  • Paid counselling plus financial and legal advice.
  • Optional social and wellbeing events and support with reasonable adjustments during the application process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →