Cyber Operations Senior Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cyber Operations Senior Engineer (Cybersecurity): Responsible for designing and developing security tooling and automation across platforms, ensuring best practices, and maintaining high standards. Focus on continual tuning, enrichment, and optimization across Sentinel and aligning with other SIEM tools.
Location: Hybrid (Manchester, Marlow) with 2 days in the office and 3 days working from home
Company
is one of the UK's leading IT infrastructure providers and a FTSE 250 listed company.
What you will do
- Work with customers and internal stakeholders to identify development and improvement opportunities.
- Provide on-call support alongside other senior team members as part of a continuous on-call rota.
- Design and develop security tooling, automation, best practices, and efficiency across platforms.
- Deliver end-to-end SIEM/Sentinel engineering by onboarding customers, configuring data connectors, integrations, KQL, automation, dashboards, and reporting.
- Drive continual tuning, enrichment, and optimization across Sentinel and align with other SIEM tools.
Requirements
- Knowledge and understanding of incident response frameworks such as NIST CSF, SOC2, or equivalent.
- Knowledge and understanding of information security architecture and IT security policies relevant to logging.
- Organized, with strong communication skills, both written and oral, and with the ability to translate and deliver technical information to a non-technical audience.
- Customer-focused and proactive in resolving technical issues and challenges.
- Prior experience working within a Managed Service Provider or MSSP organization is strongly preferred.
- Strong experience working with KQL, ADX, data connectors, GitHub, and other components of MS Sentinel.
Nice to have
- Experience with other SIEM and related information security management platforms desirable, such as AlienVault, Elastic, EDR/MDR tools, vulnerability management platforms etc.
- Demonstrable knowledge of SIEM data modeling, event normalization, and enrichment strategies.
- Ability to perform requirements analysis and use-case modeling to define logging/integration needs for new and evolving services.
Culture & Benefits
- Flexible working patterns including hybrid working, flexible hours, and flexibility around school pick up and drop offs.
- Supported by a team that celebrates individuality, encourages different perspectives, and embraces every background.
- Freedom and autonomy to realize your potential.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →