SIEM Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
SIEM Security Engineer (Elasticsearch): Designing and maintaining the ingestion of the Strategic SIEM system with an accent on threat detection, incident response, and security logging. Focus on optimizing Elasticsearch pipelines, implementing SIEM rules, and enhancing data enrichment via Kafka and threat intelligence.
Location: Hybrid (3 days in office), based in Birmingham, UK
Company
is the UK’s leading communications group, operating brands such as BT, EE, Openreach, and Plusnet.
What you will do
- Collaborate with analysts and application teams to design security data ingestion and configure Elasticsearch pipelines from Kafka.
- Design and implement SIEM solutions using Elasticsearch, optimizing rules, alerts, and dashboards for efficient threat detection.
- Write efficient Elasticsearch queries for security event retrieval and manage SIEM infrastructure performance.
- Contribute to security engineering projects and integrate SIEM with associated incident response systems.
- Stay informed about emerging threats and apply security best practices to enhance the overall security posture.
Requirements
- 5+ years of engineering experience in delivering cybersecurity solutions.
- Proven experience in SIEM Detection Engineering and log source onboarding and normalization.
- Hands-on experience with cybersecurity technologies such as NGFW, Proxies, and IAM solutions.
- Strong understanding of MITRE ATT&CK and modern cyber threat techniques.
- Bachelor’s or Master’s degree in Computer Science, Information Systems, Engineering, or a related field.
- Must be based in or able to commute to Birmingham, UK for a hybrid (3 days in office) schedule.
Nice to have
- Experience with the Elastic Stack (ELK), OpenStack, and Kubernetes (K8S).
- Knowledge of Linux, Windows, and Network Administration.
- Proficiency with Git, DevOps practices, Terraform, and Ansible.
- Familiarity with the Telecoms Security Act (TSA) and regulatory frameworks.
- Relevant cybersecurity professional qualifications.
Culture & Benefits
- 10% on-target annual bonus and a market-leading pension scheme (10% company contribution).
- Comprehensive parental leave: 18 weeks full pay and 8 weeks half pay.
- 24/7 online private GP access for employees and their immediate family.
- Market-leading paid carers leave (up to 2 weeks).
- Discounted EE and BT products, including mobile and broadband.
- Flexible holiday purchase scheme.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →