Type: Full Time / Contract / Inside IR35
Duration: 6 months initial
Start Date: ASAP
Location: Remote / On-Site Occasionally
Must have valid SC Clearance
Overview
We are seeking an innovative and highly experienced Senior Cyber Security Engineer to join our client's Security Orchestration, Automation, and Response (SOAR) Engineering team. In this role, you will serve as a primary technical resource responsible for developing automation and response workflows to detect, resolve, and mitigate cyber security threats. Supporting a Critical National Infrastructure (CNI) project, you will combine advanced big data analytics with automation scripting to protect vital national services from cyber disruption.
Responsibilities
- Automation & Response Development: Partner directly with the Incident Response team to design, build, and deploy automated playbooks and workflows within Splunk SOAR to maximize operational efficiency.
- Platform Subject Matter Expertise: Act as a technical SME for big data analytics, automated detection, and response strategy across Splunk Enterprise Security and Splunk SOAR platforms.
- Analytics & Quality Assurance: Produce robust system analytics to validate automation behaviours and assumptions. Lead quality assurance reviews on code and workflows built by other team members prior to production release.
- Mentoring & Leadership: Provide technical guidance and mentorship to junior members of the SOAR engineering team to uplift overall technical capability.
- Governance & Change Control: Recommend, develop, and release new automated security use cases while ensuring all system changes are strictly documented in line with industry-standard Change Management frameworks.
Requirements
- Strong background in cyber security automation with a deep understanding of security incident response methodologies.
- Core hands-on engineering experience using Splunk, Splunk Enterprise Security (ES), and Splunk SOAR (formerly Phantom).
- Solid experience working with multi-petabyte data lakes and large-scale SIEM environments.
- Practical knowledge of security frameworks including MITRE ATT&CK, NIST, and their application within automated playbooks.
- Strong programming and scripting capabilities (Python preferred; experience with Java, Perl, R, or C++ is a plus).
- A holistic understanding of the full technology stack, including networks, operating systems (Windows/Linux), applications, databases, and endpoints.
- Detail-oriented with excellent interpersonal and communication skills, comfortable working independently to tight deadlines in a fast-paced environment.Endpoint