Cyber Security Engineer

ZKM Consulting

West Midlands

Hybrid

GBP 90,000 - 110,000

Full time

7 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

ZKM Consulting is seeking a Senior Cyber Security Engineer to join the SOAR engineering team, developing automation and response workflows to protect critical national services. You will work on Splunk Enterprise Security and Splunk SOAR, handling big data analytics and automated detection in a high-stakes environment.

The role requires strong automation skills, incident response expertise, and mentoring abilities, with a focus on secure, scalable playbooks and rigorous Change Management

Qualifications

  • Strong background in cyber security automation and incident response.
  • Hands-on experience with Splunk ES and Splunk SOAR.
  • Experience with large-scale SIEM environments and multi-petabyte data lakes.
  • Knowledge of MITRE ATT&CK, NIST frameworks in automated playbooks.
  • Strong programming/scripting (Python preferred; Java/Perl/R/C++ a plus).

Responsibilities

  • Design, build, and deploy automated playbooks/workflows within Splunk SOAR.
  • Act as SME for big data analytics, detection, and response across Splunk platforms.
  • Produce robust analytics to validate automation and lead QA on code/workflows.
  • Mentor junior SOAR engineers to uplift team capability.
  • Develop and release new automated security use cases with documented Change Management.

Skills

Cyber security automation
Incident response methodologies
Big data analytics
Automation scripting
Mentorship

Tools

Splunk
Splunk ES
Splunk SOAR

Job description

Type: Full Time / Contract / Inside IR35

Duration: 6 months initial

Start Date: ASAP

Location: Remote / On-Site Occasionally

Must have valid SC Clearance

Overview

We are seeking an innovative and highly experienced Senior Cyber Security Engineer to join our client's Security Orchestration, Automation, and Response (SOAR) Engineering team. In this role, you will serve as a primary technical resource responsible for developing automation and response workflows to detect, resolve, and mitigate cyber security threats. Supporting a Critical National Infrastructure (CNI) project, you will combine advanced big data analytics with automation scripting to protect vital national services from cyber disruption.

Responsibilities
  • Automation & Response Development: Partner directly with the Incident Response team to design, build, and deploy automated playbooks and workflows within Splunk SOAR to maximize operational efficiency.
  • Platform Subject Matter Expertise: Act as a technical SME for big data analytics, automated detection, and response strategy across Splunk Enterprise Security and Splunk SOAR platforms.
  • Analytics & Quality Assurance: Produce robust system analytics to validate automation behaviours and assumptions. Lead quality assurance reviews on code and workflows built by other team members prior to production release.
  • Mentoring & Leadership: Provide technical guidance and mentorship to junior members of the SOAR engineering team to uplift overall technical capability.
  • Governance & Change Control: Recommend, develop, and release new automated security use cases while ensuring all system changes are strictly documented in line with industry-standard Change Management frameworks.
Requirements
  • Strong background in cyber security automation with a deep understanding of security incident response methodologies.
  • Core hands-on engineering experience using Splunk, Splunk Enterprise Security (ES), and Splunk SOAR (formerly Phantom).
  • Solid experience working with multi-petabyte data lakes and large-scale SIEM environments.
  • Practical knowledge of security frameworks including MITRE ATT&CK, NIST, and their application within automated playbooks.
  • Strong programming and scripting capabilities (Python preferred; experience with Java, Perl, R, or C++ is a plus).
  • A holistic understanding of the full technology stack, including networks, operating systems (Windows/Linux), applications, databases, and endpoints.
  • Detail-oriented with excellent interpersonal and communication skills, comfortable working independently to tight deadlines in a fast-paced environment.Endpoint
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOAR Engineer
SOAR Engineer

Sanderson Government and Defence • Bradley Stoke

On-site
GBP 65,000 - 90,000
Cyber Security Engineer
Cyber Security Engineer

Tatton Recruitment • Stevenage

On-site
GBP 170,000 - 185,000
Cyber Security Engineer
Cyber Security Engineer

Guidant Global • Stevenage

On-site
GBP 109,000 - 142,000
Cyber Security Engineer
Cyber Security Engineer

Certain Advantage • Stevenage

Hybrid
GBP 170,000 - 184,000
Cyber Security Engineer
Cyber Security Engineer

Advantage Resourcing UK Ltd • Stevenage

On-site
GBP 174,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

Advanced Resource Managers Ltd • Stevenage

On-site
GBP 107,000 - 146,000
SOAR Engineer
SOAR Engineer

Sanderson Government and Defence • Cheltenham

On-site
GBP 90,000 - 110,000
Cyber Security Engineer
Cyber Security Engineer

Matchtech • Stevenage

On-site
GBP 76,000 - 127,000
Cyber Security Engineer
Cyber Security Engineer

Infosec • Stevenage

On-site
GBP 76,000 - 127,000
SOAR Engineer
SOAR Engineer

Sanderson Government and Defence • Warmley

On-site
GBP 70,000 - 110,000