Siem Detection Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Siem Detection Engineer (Cybersecurity): Enhancing threat detection capabilities using Google Security Operations (Chronicle SIEM) and supporting security automation across cloud and hybrid environments. Focus on designing detection logic, log ingestion pipelines, automation playbooks, and operational dashboards to maintain robust security posture.
Location: Southampton, London, or Home Based in the UK
Company
is a leading wealth management business in the UK, overseeing £126.3 billion in customer investments and offering financial advice, investment platforms, and discretionary fund management.
What you will do
- Support onboarding and parsing of logs from cloud platforms, infrastructure, third-party SaaS, and security tools.
- Design, implement, and tune detection rules using YARA-L and other query languages.
- Develop and maintain automation playbooks integrating with Microsoft 365 Defender, Entra ID, CrowdStrike, and collaboration tools.
- Create and maintain operational SIEM dashboards for real-time visibility into detection metrics and system health.
- Collaborate with SOC partners, threat intelligence, and engineering teams to align detection strategies with business risks.
- Participate in incident response exercises and improve SIEM detection and prevention controls.
Requirements
- Location: Must be based in or able to work from Southampton, London, or home within the UK.
- 5+ years in cybersecurity roles including SOC, detection engineering, and incident response.
- 3+ years hands-on experience with Google SecOps (Chronicle SIEM) or similar platforms.
- Proficiency in YARA-L, SPL, KQL, and experience with log ingestion pipelines and custom parser development.
- Strong knowledge of cloud platforms (Azure) and security controls, Microsoft Defender Suite, CrowdStrike, and SOAR platforms.
- Understanding of MITRE ATT&CK framework, threat modeling, and incident detection frameworks.
Nice to have
- Bachelor's degree in Cybersecurity, Intelligence Studies, Computer Science, or related field.
- Certifications such as CISSP, CISM, CCSP, GIAC, CPIA.
Culture & Benefits
- 26 days holiday (182 hours).
- Participation in Incentive Scheme based on business performance.
- Non-contributory company pension scheme with option for personal contributions.
- Private medical insurance with options to cover family members.
- Life assurance at 4x salary and income protection after 26 weeks of absence.
- Flexible benefits available for UK employees via salary deduction.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →