Principal Security Consultant - SIEM
JR United Kingdom
City Of London
On-site
GBP 60,000 - 90,000
Full time
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
Job summary
A leading company in the UK is looking for a SIEM Lead to oversee the design and implementation of enterprise-grade SIEM platforms. The role involves providing technical leadership, optimizing logging processes, and ensuring alignment of security operations with business goals. Candidates should have strong expertise in SIEM tools like Splunk and Azure Sentinel and a deep understanding of threat detection frameworks.
Responsibilities
- Lead design, deployment, and tuning of enterprise SIEM platforms.
- Collaborate on logging requirements and detection rules.
- Oversee integration of data sources from various layers.
Skills
Expertise in SIEM design, deployment, and optimization
Hands-on experience with major SIEM platforms
Deep understanding of log ingestion and parsing
Strong grasp of the MITRE ATT&CK framework
Experience with cloud logging and monitoring
Experience with threat modeling and cloud security
Role
- Lead the design, deployment, and tuning of enterprise-grade SIEM platforms (e.g., Splunk, Azure Sentinel, etc.)
- Collaborate with stakeholders to define logging requirements, use cases, detection rules, and dashboards
- Oversee integration of data sources from cloud, on-premises, endpoint, network, and application layers
- Create and maintain detection rules, correlation logic, and alerts tailored to specific threat scenarios
- Provide technical leadership and mentorship to team members
- Work closely with SOC teams to align SIEM capabilities with business objectives
- Conduct SIEM health checks, performance tuning, and capacity planning
Skills
- Expertise in SIEM design, deployment, and optimization
- Hands-on experience with one or more major SIEM platforms (e.g., Splunk, Sentinel, etc.)
- Deep understanding of log ingestion, parsing, normalization, and enrichment
- Strong grasp of the MITRE ATT&CK framework, threat detection, and alert logic
- Experience with cloud logging and monitoring (AWS CloudTrail, Azure Monitor, GCP, etc.)
- Experience with threat modeling, cloud security, or Identity and Access Management is desirable