About Us
Operating within the energy, utilities and waste sector, this organisation supports services and infrastructure that communities and businesses rely on every day. Its technology landscape spans environments where resilient operations, dependable data and disciplined risk management are essential. Cyber security therefore has a direct role in maintaining service continuity and protecting critical operational capability.
The security function focuses on practical protection across enterprise, cloud and operational technology environments. It combines monitoring, engineering and response disciplines to identify emerging threats, strengthen defensive controls and improve the resilience of essential services.
Job Description
The Cyber Security Engineer will design, operate and improve the technical capabilities used to detect, investigate and contain cyber threats. The position combines security engineering with operational delivery, covering SIEM development, telemetry quality, cloud controls, detection content and incident support across a complex infrastructure estate.
Success will be measured by the reliability of security monitoring, the quality of actionable alerts and the effectiveness of controls across AWS, Azure and connected operational environments. You will translate security requirements into maintainable engineering solutions, resolve technical weaknesses and provide clear insight to security and technology stakeholders.
Working across the wider security function, you will help shape monitoring and response practices rather than simply maintaining existing tools. The role requires sound technical judgement, structured investigation and the confidence to improve capabilities in an environment where availability, compliance and risk reduction are all important outcomes.
Key Responsibilities
- Engineer, administer and continuously improve the Elastic SIEM platform and related security tooling.
- Develop detection logic, dashboards, alert workflows and monitoring use cases that support effective threat identification.
- Design reliable pipelines for log collection, parsing, transformation, normalisation and integration.
- Assess security telemetry for completeness, accuracy and operational value, then address gaps with appropriate technical solutions.
- Strengthen preventative and detective controls across AWS, Azure and relevant operational technology environments.
- Support Security Operations Centre and Network Operations Centre teams with investigation, triage and technical escalation.
- Contribute to Data Loss Prevention initiatives, including control design, tuning, testing and operational adoption.
- Investigate suspicious activity and security events, documenting findings and feeding lessons into improved detection and response.
- Work with security architecture, cloud, governance, infrastructure and technology teams to deliver proportionate security improvements.
- Translate business and operational requirements into clear engineering priorities, implementation plans and measurable outcomes.
- Maintain technical documentation, configuration records and evidence required for effective governance and assurance.
- Monitor platform performance, resolve defects and identify opportunities to automate repetitive security engineering activities.
Requirements
- Demonstrable experience in cyber security engineering, security operations, detection engineering or a closely related technical discipline.
- Practical experience administering or developing SIEM capabilities, with Elastic knowledge strongly advantageous.
- Understanding of security telemetry architecture, including collection, ingestion, parsing, enrichment and retention.
- Experience creating or tuning detection rules, correlation logic, dashboards, alerts or investigative workflows.
- Working knowledge of security principles across AWS and Azure cloud environments.
- Exposure to incident investigation, event triage, threat analysis and the improvement of response procedures.
- Familiarity with Data Loss Prevention concepts and the operational challenges of implementing security controls.
- Ability to troubleshoot integrations, identify root causes and restore reliable security monitoring services.
- Experience working with infrastructure, networking, endpoint, identity or operational technology teams.
- Strong analytical capability, with the discipline to distinguish material risk from routine security noise.
- Clear written and verbal communication skills, including the ability to explain technical issues to varied stakeholders.
- Confidence managing competing priorities and influencing decisions in a regulated or operationally sensitive environment.
- Sound understanding of security governance, access control, change management and evidence-based assurance.
- Relevant professional certifications or equivalent practical experience in cyber security, cloud or infrastructure disciplines.
- Commitment to continuous learning as threat techniques, platforms and defensive practices evolve.
- Eligibility to work in the United Kingdom and willingness to meet any role-specific screening or access requirements.
Benefits
- Work on cyber security challenges that directly support the resilience of essential energy, utilities and waste services.
- Gain broad exposure to SIEM engineering, cloud security, operational technology and security operations within one role.
- Influence the development of detection, monitoring and response capabilities rather than working only within established processes.
- Access opportunities to deepen technical expertise across Elastic, AWS, Azure and defensive security engineering practices.
- Collaborate with experienced specialists across security architecture, governance, cloud, infrastructure and operations.
- Build a visible portfolio of improvements linked to measurable monitoring quality, threat detection and risk reduction outcomes.
- Benefit from a structured professional environment where documentation, technical quality and responsible delivery are valued.
- Develop transferable experience in a sector where resilience, continuity and security assurance have immediate operational importance.
Other
The role is based in Manchester and will suit an engineer who combines hands-on technical capability with a strong understanding of operational risk. Experience from a security operations centre, managed security service provider, cloud platform, infrastructure team or regulated environment may provide a strong foundation.
Applications are encouraged from professionals who can demonstrate practical results, including improved telemetry coverage, more effective detections, stronger cloud controls or faster investigation workflows. The successful candidate will bring curiosity, ownership and the judgement to make security improvements that remain effective in day-to-day operations.