A leading technology provider seeks a DV-cleared SOC Engineer for a hybrid role in Bristol. This position focuses on detection engineering, SIEM optimisation, and incident response automation. Key responsibilities include developing detection rules in SIEM platforms like Splunk, automating workflows, and supporting incident investigations. The ideal candidate has experience in SOC Engineering, strong scripting skills in Python or PowerShell, and an understanding of threat detection frameworks. A minimum of 3 days per week on site is required.
Qualifications
Proven experience in SOC Engineering or as an advanced SOC Analyst.
Hands-on experience with SIEM platforms and tuning detection.
Strong scripting and automation skills, particularly in Python and PowerShell.
Responsibilities
Develop and tune detection rules and use cases in SIEM.
Automate SOC workflows and incident response processes.
Support and lead incident investigations and escalations.
Integrate threat intelligence into monitoring and detection.
Maintain SOC playbooks and improve tooling and processes.
Skills
SOC Engineering Experience
SIEM Platforms Expertise
Scripting/Automation (Python, PowerShell)
Threat Detection Understanding
Tools
Splunk
QRadar
Job description
A leading technology provider seeks a DV-cleared SOC Engineer for a hybrid role in Bristol. This position focuses on detection engineering, SIEM optimisation, and incident response automation. Key responsibilities include developing detection rules in SIEM platforms like Splunk, automating workflows, and supporting incident investigations. The ideal candidate has experience in SOC Engineering, strong scripting skills in Python or PowerShell, and an understanding of threat detection frameworks. A minimum of 3 days per week on site is required.