Security Engineer (SIEM integration) - 6 Month Fixed-Term Contract
We are a leading international professional services organisation with a strong global presence across Europe, the Americas, the Middle East and Asia. We provide specialist advisory services to multinational organisations, financial institutions and investment firms, operating within highly regulated environments.
We are seeking an experienced Security Engineer (SIEM integration) to join our Information Security Operations team on a 6-month fixed-term contract. This role will play a key part in enhancing and maturing our security monitoring and detection capabilities.
The Role
As a Security Engineer, you will focus on strengthening and optimising our Security Information and Event Management (SIEM) platform. You will be responsible for onboarding new log sources, improving data pipelines, developing advanced detection use cases, and supporting incident response activities.
This is an excellent opportunity for a security professional who enjoys building scalable, high-performing security monitoring environments and working in a collaborative, fast-paced setting.
You will report to the Information Security Operations Manager and work closely with the wider security team and internal stakeholders to improve the organisation's overall security posture.
Key Responsibilities
SIEM Engineering & Optimisation
Enhance and optimise the SIEM platform to improve performance, coverage, and detection accuracy
Assess SIEM architecture and recommend improvements across ingestion, parsing, correlation, and storage
Implement automation and orchestration (SOAR) to streamline security operations
Log Source Onboarding & Integration
Identify and onboard log sources across cloud, network, endpoint, identity, and application layers
Develop custom parsers, connectors, and ingestion workflows
Collaborate with internal teams and vendors to ensure high-quality telemetry
Detection Engineering
Design and implement detection use cases aligned to frameworks such as MITRE ATT&CK
Build and tune correlation rules, alerts, dashboards, and anomaly detections
Continuously improve detection quality and reduce false positives
SOC & Incident Response Support
Partner with SOC analysts to refine detection logic
Support investigations through advanced SIEM querying and data analysis
Provide subject matter expertise during complex security incidents
Documentation & Governance
Maintain clear documentation of SIEM architecture, data models, and detection logic
Ensure alignment with internal policies, compliance requirements, and industry standards
Skills & Experience
Technical Expertise
Strong hands-on experience with SIEM platforms (eg Splunk, Microsoft Sentinel, QRadar, Elastic, LogRhythm, ArcSight, Exabeam)
Knowledge of log formats (JSON, syslog, XML, CEF) and ingestion methods (APIs, agents, Kafka, Event Hubs)
Experience in detection engineering, threat modelling, and attacker behaviour analysis
Familiarity with SOAR tools and automation workflows
Security Knowledge
Understanding of networks, Windows/Linux systems, cloud platforms (Azure, AWS, GCP), identity systems, and endpoint security tools
Knowledge of frameworks such as MITRE ATT&CK and threat hunting methodologies
Essential Requirements
Degree (or equivalent experience) in a computing or related discipline
Proven experience across IT infrastructure and information security
Relevant certifications (eg GIAC, CISSP, SSCP, Microsoft SC-200/SC-100, CompTIA Security certifications)
Strong Scripting skills (Python, PowerShell, or similar)
Excellent communication skills with the ability to engage stakeholders at all levels
Proactive, self-starting approach with strong problem-solving ability
Desirable Experience
Data Loss Prevention (DLP)
Network security and secure remote access solutions
Cloud and software-defined environments (SaaS, IaaS, PaaS, DaaS)
Cyber threat intelligence and open-source intelligence tools
Disaster recovery and business continuity planning
Knowledge of data privacy regulations
Additional Information
Some out-of-hours work may be required for planned changes or security incidents
Opportunity to contribute to strategic security initiatives and service improvements
If you are a motivated Security Engineer looking to make a tangible impact within a global, highly regulated environment, we would love to hear from you.