Cyber Security Engineer (Ref: 197774)

Forsyth Barnes Consultancy

Manchester

On-site

GBP 60,000 - 90,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

SIEM engineering exposure
Cloud security focus
Risk and governance
Career development

Job summary

Forsyth Barnes Consultancy in Manchester is seeking a Cyber Security Engineer to design, operate and improve capabilities used to detect, investigate and contain cyber threats across a complex infrastructure.

You will develop SIEM content, dashboards and alert workflows, support SOC/NOC, and collaborate with security architecture, cloud, governance and infrastructure teams to deliver proportionate improvements while maintaining governance and evidence-based assurance.

Qualifications

  • Demonstrable experience in cyber security engineering or related discipline.
  • Experience administering or developing SIEM capabilities, with Elastic knowledge advantageous.
  • Ability to design and tune detection rules, correlation logic, dashboards, alerts or investigative workflows.
  • Eligibility to work in the United Kingdom and willingness to meet role-specific screening requirements.

Responsibilities

  • Engineer, administer and continuously improve the Elastic SIEM platform and related security tooling.
  • Develop detection logic, dashboards, alert workflows and monitoring use cases that support effective threat identification.
  • Design reliable pipelines for log collection, parsing, transformation, normalisation and integration.
  • Assess security telemetry for completeness, accuracy and operational value, then address gaps with technical solutions.
  • Strengthen preventative and detective controls across AWS, Azure and OT environments.
  • Support SOC and NOC teams with investigation, triage and technical escalation.
  • Contribute to Data Loss Prevention initiatives and testing.
  • Investigate suspicious activity and document findings for improved detection and response.

Skills

Elastic SIEM
Threat detection
Incident response
Cloud security (AWS/Azure)
Security monitoring
Log analytics
Security governance

Education

Bachelor's degree in a cybersecurity-related field

Tools

Elastic Stack
AWS
Azure

Job description

About Us

Operating within the energy, utilities and waste sector, this organisation supports services and infrastructure that communities and businesses rely on every day. Its technology landscape spans environments where resilient operations, dependable data and disciplined risk management are essential. Cyber security therefore has a direct role in maintaining service continuity and protecting critical operational capability.

Job Description

The Cyber Security Engineer will design, operate and improve the technical capabilities used to detect, investigate and contain cyber threats. The position combines security engineering with operational delivery, covering SIEM development, telemetry quality, cloud controls, detection content and incident support across a complex infrastructure estate.

Success will be measured by the reliability of security monitoring, the quality of actionable alerts and the effectiveness of controls across AWS, Azure and connected operational environments. You will translate security requirements into maintainable engineering solutions, resolve technical weaknesses and provide clear insight to security and technology stakeholders.

Working across the wider security function, you will help shape monitoring and response practices rather than simply maintaining existing tools. The role requires sound technical judgement, structured investigation and the confidence to improve capabilities in an environment where availability, compliance and risk reduction are all important outcomes.

Key Responsibilities
  • Engineer, administer and continuously improve the Elastic SIEM platform and related security tooling.
  • Develop detection logic, dashboards, alert workflows and monitoring use cases that support effective threat identification.
  • Design reliable pipelines for log collection, parsing, transformation, normalisation and integration.
  • Assess security telemetry for completeness, accuracy and operational value, then address gaps with appropriate technical solutions.
  • Strengthen preventative and detective controls across AWS, Azure and relevant operational technology environments.
  • Support Security Operations Centre and Network Operations Centre teams with investigation, triage and technical escalation.
  • Contribute to Data Loss Prevention initiatives, including control design, tuning, testing and operational adoption.
  • Investigate suspicious activity and security events, documenting findings and feeding lessons into improved detection and response.
  • Work with security architecture, cloud, governance, infrastructure and technology teams to deliver proportionate security improvements.
  • Translate business and operational requirements into clear engineering priorities, implementation plans and measurable outcomes.
  • Maintain technical documentation, configuration records and evidence required for effective governance and assurance.
  • Monitor platform performance, resolve defects and identify opportunities to automate repetitive security engineering activities.
Requirements
  • Demonstrable experience in cyber security engineering, security operations, detection engineering or a closely related technical discipline.
  • Practical experience administering or developing SIEM capabilities, with Elastic knowledge strongly advantageous.
  • Understanding of security telemetry architecture, including collection, ingestion, parsing, enrichment and retention.
  • Experience creating or tuning detection rules, correlation logic, dashboards, alerts or investigative workflows.
  • Working knowledge of security principles across AWS and Azure cloud environments.
  • Exposure to incident investigation, event triage, threat analysis and the improvement of response procedures.
  • Familiarity with Data Loss Prevention concepts and the operational challenges of implementing security controls.
  • Ability to troubleshoot integrations, identify root causes and restore reliable security monitoring services.
  • Experience working with infrastructure, networking, endpoint, identity or operational technology teams.
  • Strong analytical capability, with the discipline to distinguish material risk from routine security noise.
  • Clear written and verbal communication skills, including the ability to explain technical issues to varied stakeholders.
  • Confidence managing competing priorities and influencing decisions in a regulated or operationally sensitive environment.
  • Sound understanding of security governance, access control, change management and evidence-based assurance.
  • Relevant professional certifications or equivalent practical experience in cyber security, cloud or infrastructure disciplines.
  • Commitment to continuous learning as threat techniques, platforms and defensive practices evolve.
  • Eligibility to work in the United Kingdom and willingness to meet any role-specific screening or access requirements.
Benefits
  • Work on cyber security challenges that directly support the resilience of essential energy, utilities and waste services.
  • Gain broad exposure to SIEM engineering, cloud security, operational technology and security operations within one role.
  • Influence the development of detection, monitoring and response capabilities rather than working only within established processes.
  • Access opportunities to deepen technical expertise across Elastic, AWS, Azure and defensive security engineering practices.
  • Collaborate with experienced specialists across security architecture, governance, cloud, infrastructure and operations.
  • Build a visible portfolio of improvements linked to measurable monitoring quality, threat detection and risk reduction outcomes.
  • Benefit from a structured professional environment where documentation, technical quality and responsible delivery are valued.
  • Develop transferable experience in a sector where resilience, continuity and security assurance have immediate operational importance.
Other

The role is based in Manchester and will suit an engineer who combines hands‑on technical capability with a strong understanding of operational risk. Experience from a security operations centre, managed security service provider, cloud platform, infrastructure team or regulated environment may provide a strong foundation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer (REF 197774)
Cyber Security Engineer (REF 197774)

Forsyth Barnes • Manchester

On-site
GBP 50,000 - 70,000
Cyber Security Engineer
Cyber Security Engineer

Castle Employment Agency Ltd • Beverley

On-site
GBP 42,000 - 60,000
Security Engineer
Security Engineer

TRIA • Manchester

On-site
GBP 60,000 - 90,000
Cyber Security Engineer
Cyber Security Engineer

Gravitas Recruitment Group (Global) Ltd • Greater London

On-site
GBP 51,000 - 85,000
Cyber Security Engineer
Cyber Security Engineer

John Lewis • Stevenage

On-site
GBP 160,000 - 192,000
Cyber Security Engineer
Cyber Security Engineer

Digital Waffle • Manchester

On-site
GBP 45,000 - 65,000
Cyber Security Engineer
Cyber Security Engineer

Seetec Business Technology Centre • Hockley

Hybrid
GBP 49,000 - 53,000
25 days leave
Bank Holidays
Birthday day off
+7
Senior Cyber Security Engineer (EDR)
Senior Cyber Security Engineer (EDR)

Sanderson Government & Defence • Manchester

On-site
GBP 55,000 - 85,000
Hybrid working locations
Benefits package
Cyber Security Engineer
Cyber Security Engineer

Matchtech • Stevenage

On-site
GBP 76,000 - 127,000
Cyber Security Engineer
Cyber Security Engineer

Infosec • Stevenage

On-site
GBP 76,000 - 127,000