Splunk SIEM Engineer

  • Square One Resources
  • Manchester, Lancashire
  • 28/07/2026
Contractor Information Technology Telecommunications

Job Description

Splunk SIEM Engineer

Location: Manchester ( 3 days on site )

Contract Duration: Until 30 November 2026

IR35 Status: Inside IR35

Day Rate:500-550

Start Date:11/08/2026

About the Role

We are seeking an experienced Splunk SIEM Engineer to join a leading organisation within the Financial Services sector. You will be responsible for designing, developing, administering, and enhancing enterprise SIEM capabilities while working across modern security technologies including Splunk Enterprise Security, Splunk Cloud, Microsoft Sentinel, and Cribl Stream.

This is an exciting opportunity to work within a large-scale enterprise environment, helping improve threat detection, security monitoring, automation, and incident response capabilities.

Essential Experience

  • Strong experience administering and developing Splunk Enterprise.
  • Extensive experience with Splunk Enterprise Security (ES), including:
  • Administering, managing, and maintaining SIEM environments.
  • Developing SIEM use cases and correlation searches.
  • Strong understanding of Splunk Data Models.
  • Hands-on experience with Splunk Cloud.
  • Hands-on experience with Microsoft Sentinel.
  • Experience with Cribl Stream, including log ingestion, data routing, transformation, parsing, and data normalisation.
  • Experience working in enterprise Security Operations environments, including threat detection, incident response, and security event analysis.
  • Experience with SOAR platforms, playbook development, and security automation.
  • Good understanding of network security, including Firewalls, proxies, network architecture, and common attack vectors.
  • Excellent technical documentation and communication skills.

Desirable Skills

  • AWS and Azure cloud security.
  • Containerised environments and SaaS security solutions.
  • Python, PowerShell, SPL, KQL, and SQL.
  • EDR, UBA, CASB, CSPM, vulnerability assessment, and threat intelligence platforms.
  • CI/CD tools such as GitLab and Jenkins.
  • Infrastructure as Code using Chef or Ansible.
  • Knowledge of SOX, PCI-DSS, and GDPR.
  • Incident response and digital forensics experience.

Preferred Certifications

  • Bachelor's degree.
  • CISSP
  • GCIH
  • GCFA
  • Splunk Certified Architect
  • Microsoft Sentinel

Interested?

If this opportunity is of interest, we'd love to hear from you.

Send your CV or any questions

If this role isn't quite the right fit but you know someone who may be suitable, please feel free to share this opportunity with them.