Hybrid SIEM Engineer - Elasticsearch & Threat Detection

BT Group

Birmingham

Hybrid

GBP 65,000 - 90,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

10% on target annual bonus
Private GP 24/7 for you and family
Market-leading pension scheme

Job summary

BT Group in Birmingham is seeking a SIEM Application Engineer to support the development, deployment and operation of BT's strategic SIEM. You will design and maintain ingestion pipelines using Elasticsearch, Logstash and Kibana, and work with Kafka sources.

The role requires a solid software engineering background, scripting, and hands-on experience with Kubernetes and DevOps tools. Based in the Birmingham office, it is a hybrid role with three days in the office.

Qualifications

  • The candidate must have a software engineering background with security focus.
  • Proven experience with SIEM components and security logging/monitoring.
  • Hands-on knowledge of Elasticsearch, Logstash and Kibana in production.
  • Experience integrating data from Kafka sources and threat intel feeds.
  • Familiarity with Kubernetes and DevOps pipelines (ArgoCD, Gitlab).
  • Strong problem solving and attention to detail; quick learner.

Responsibilities

  • Data ingestion and enrichment via Elasticsearch pipelines and Kafka sources.
  • Develop SIEM solutions in collaboration with security analysts and architects.
  • Optimize SIEM rules, alerts and dashboards for threat detection.
  • Write efficient Elasticsearch queries and tune performance.
  • Maintain SIEM infrastructure and monitor reliability and security.
  • Collaborate on security engineering projects and incident response.

Skills

Software Engineering
Scripting
Kubernetes
Elasticsearch
Kafka
ArgoCD
Gitlab pipelines
YAML
Helm
Ansible
Basic networking
Troubleshooting
Willingness to learn
Attention to detail

Tools

Elasticsearch
Logstash
Kibana
Kafka
ArgoCD
Gitlab pipelines
YAML
Helm
Ansible
Linux
Windows

Job description

BT Group in Birmingham is seeking a SIEM Application Engineer to support the development, deployment and operation of BT's strategic SIEM. You will design and maintain ingestion pipelines using Elasticsearch, Logstash and Kibana, and work with Kafka sources.

The role requires a solid software engineering background, scripting, and hands-on experience with Kubernetes and DevOps tools. Based in the Birmingham office, it is a hybrid role with three days in the office.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Engineer: Threat Detection & Elasticsearch Specialist
SIEM Engineer: Threat Detection & Elasticsearch Specialist

BT Group • Birmingham

Hybrid
GBP 65,000 - 95,000
10% on target annual bonus
Online private GP 24/7 for you and a4"
Pension scheme – 5% from you and 10%来自
SIEM Application Engineer
SIEM Application Engineer

BT Group • Birmingham

Hybrid
GBP 65,000 - 90,000
10% on target annual bonus
Private GP 24/7 for you and family
Market-leading pension scheme
SIEM Security Engineer
SIEM Security Engineer

BT Group • Birmingham

On-site
GBP 65,000 - 95,000
10% on target annual bonus
Online private GP 24/7 for you and a4"
Pension scheme – 5% from you and 10%来自
Senior SIEM & Security Platform Engineer (Hybrid)
Senior SIEM & Security Platform Engineer (Hybrid)

Hackajob Ltd • Bath

Hybrid
GBP 44,000 - 62,000
Generous leave
Pension with employer contrib
Mental health support
+3
Security Data Platform Engineer — Elastic SIEM & Cloud
Security Data Platform Engineer — Elastic SIEM & Cloud

Barlowe LLP • Greater London

On-site
GBP 120,000 - 180,000
Discretionary bonus
Lunch via Just Eat for Business
35 days leave
+5
Cyber Operations Security Engineer — SIEM & Sentinel (Hybrid)
Cyber Operations Security Engineer — SIEM & Sentinel (Hybrid)

Softcat plc • Manchester

Hybrid
GBP 55,000 - 75,000
Pension
Share incentive plan
Life Assurance
+5
Senior SOC Analyst & Shift Lead - Hybrid
Senior SOC Analyst & Shift Lead - Hybrid

BAE Systems Digital Intelligence • Manchester

Hybrid
GBP 60,000 - 90,000
£5,000 referral bonus
Hybrid working
Junior Security Engineer
Junior Security Engineer

Cybanetix • Greater London

On-site
GBP 50,000 - 70,000
Hands-on experience with modern SIEM, EDR, and Azure security tooling
Structured progression into security engineering
Mentorship from senior engineers and architects
Security Platform Engineer - SIEM & Automation
Security Platform Engineer - SIEM & Automation

Infosec • Stevenage

On-site
GBP 76,000 - 127,000
Senior SIEM & Detection Engineer (Sentinel/Splunk)
Senior SIEM & Detection Engineer (Sentinel/Splunk)

Sopra Steria Limited • Farnborough

On-site
GBP 65,000 - 90,000
Professional development
Mentoring and knowledge sharing