(UK) SIEM Engineer - #143157

Avatar International SA


Date: 2 weeks ago
City: Maidenhead
Contract type: Full time
£60-80K per annum + incentive scheme, medical insurance, pension, PDP (personal development plan) working with a Mentor to keep up to date with CyberSecurity certifications.

This role is only fully remote if the candidate stays further than 80 miles from Maidenhead, otherwise they benefit from a hybrid-working arrangement with Wednesdays compulsory in the office, and will be travelling to client meetings as and when required for the role.

About The Role

The primary responsibility of this role is to integrate log sources into Sentinel, using standard data connectors, troubleshooting and enhancing data connectors, developing custom connectors where required and optimising log ingestion.

The Key Responsibilities Are

  • Responsible for end-to-end integration of logs into Sentinel.
  • Scope, plan and track log integration.
  • Research, test and advise clients on audit configuration settings for log sources, to ensure that the right logs flow into Sentinel for threat detection.
  • Deploy data connectors and troubleshoot data ingestion, including deployment of Function Apps, customisation and enhancement of Function App code where required, and development of custom log ingestion solutions.
  • Validation of log parsing, fixing and enhancing existing parsers, and development of new parsers.
  • Optimisation of collected logs to ensure the right events are collected and unnecessary events are filtered out to manage consumption and cost.
  • Documentation of solution design, and development of technical processes and procedures to
  • enhance our knowledge base and aid standardization efforts.

Secondary responsibilities:

  • Assist other Engineers in maintaining and enhancing our DevOps pipeline, to scale services across multiple clients, including code development and maintenance.
  • Sentinel health checks and periodic maintenance, e.g. data connector updates.
  • Rule fine-tuning, and integration of applicable changes from upstream rule repositories into our repo.
  • Collaborate with Analysts and client cybersecurity professionals to refine detection
  • strategies, improve detection accuracy and reduce false positives.
  • Analyse security logs from various sources including cloud platforms services, firewalls, intrusion detection systems, VPN, web application firewalls, web and email filtering, identity and access management systems, endpoint protection and EDR, and other security tools.

Qualifications and Experience:

  • Minimum of 5 years of experience in cybersecurity.
  • Minimum of 3 years of Sentinel design and implementation experience, including Linux deployment and administration.
  • Solid experience working with security logs across multiple domains - identity and access, network, system, data, application, cloud - and multiple product types, e.g. firewalls, intrusion detection systems, VPN, web application firewalls, web and email filtering, identity directories and SSO, endpoint protection and EDR, and other security tools.
  • Strong understanding of the threat landscape, common attack vectors, and threat actor tactics, techniques, procedures and tools.
  • Experience with frameworks like MITRE ATTACK.
  • Proficiency in data analysis and scripting languages (e.g., PowerShell, Python).
  • Excellent problem-solving skills, attention to detail and quality delivery.
  • Strong communication and teamwork skills.
  • Ability to deliver in a fast-paced environment.

Why Join our Client?

Competitive salary. Hybrid working arrangement for flexibility. Opportunity to work with cutting-edge technologies and a dynamic team.

How to Apply: If you’re ready to take the next step in your career, apply with your updated CV and a brief cover letter. Let’s secure the future together!

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Medical Information and Medical Operations Manager

Biogen, Maidenhead
1 week ago
About This Role As the Medical Information & Medical Operations Manager, you will play a vital role in ensuring the delivery of high-quality medical information services and operational support across the UK and Ireland. You will oversee the management of third-party providers, ensuring compliance with internal standards and national regulations. Your responsibilities will include leading the medical components of Patient...

Key Account Manager - East of England and North West London

Biogen, Maidenhead
1 week ago
About This Role Joining us as Key Account Manager, your role is central to ensuring we continue to deliver on our company ambition of expanding access for patients across our biosimilars portfolio. This role has full accountability for the development and implementation of a local business plan which aligns to our national strategy and delivers commercial results through appropriate prioritisation...

Holyport College - Teacher of Art

Royal Borough of Windsor and Maidenhead, Maidenhead
3 weeks ago
The College’s full-time hours are 8.30am to 5pm Monday to Thursday, 8.30am to 3.45pm on Friday. Holyport College seeks an ambitious and effective teacher to teach Art part-time. This post will provide excellent professional development opportunities for an unqualified, newly qualified or an experienced teacher. You will teach 40% of a full teaching timetable, which can be organised to suit...