Enable job alerts via email!

Senior SIEM Content Developer

JR United Kingdom

United Kingdom

Hybrid

GBP 50,000 - 90,000

Full time

Today
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative firm is seeking a Senior SIEM Content Developer to enhance detection capabilities in a dynamic cyber defense team. This role focuses on crafting effective detection rules and analyzing real-world threats to improve security operations. You'll collaborate with experts to drive threat visibility and contribute to impactful security measures. Join a flexible, creative environment where your skills will make a significant difference in global security efforts. If you are passionate about cyber security and eager to make a real impact, this opportunity is for you.

Benefits

Flexible working hours
Collaborative team environment
Opportunity for professional growth
No micromanagement

Qualifications

  • 1-3 years of experience writing detection content for SIEM/EDR.
  • Strong grasp of attacker methodologies and detection engineering.

Responsibilities

  • Write and tune detection rules across SIEM/EDR/ELK.
  • Analyze TTPs and build behavior-based detections.

Skills

Detection Engineering
SIEM/EDR Content Development
Threat Modeling
Log Analysis
MITRE ATT&CK Framework
Threat Hunting

Education

Cyber Security Certification (GCIA, GCIH, etc.)

Tools

ELK Stack
Splunk
Version Control Systems

Job description

Social network you want to login/join with:

Client:

ECS Resource Group

Location:
Job Category:

Other

EU work permit required:

Yes

Job Views:

4

Posted:

05.05.2025

Expiry Date:

19.06.2025

Job Description:

Senior SIEM Content Developer – Detection Engineering | Cyber Security

Location: Newbury - Remote Working - Outside IR35

Team: Cyber Defence Ops

Experience Level: Mid–Senior

The Role

We’re on the hunt for a Senior SIEM Content Developer who lives and breathes detection logic. If you enjoy diving deep into attacker behaviors, writing detection rules that actually catch things (not just flag every login attempt), and helping drive threat visibility across modern tech stacks — this might be for you! You'll be part of a global cyber defence team building and refining detections across SIEM, EDR, and ELK stacks, and collaborating with security analysts, threat hunters, and incident responders to stop threats faster and smarter.

What You'll Be Doing

  • Writing & tuning detection rules across SIEM/EDR/ELK to surface real attacker behaviors (not noise)
  • Analyzing TTPs, threat intel, and real-world incidents to build behavior-based detections (beyond IOC chasing)
  • Rapid-prototyping searches mid-incident to surface lateral movement, C2, or privilege escalation attempts
  • Creating and maintaining detection logic documentation + MITRE ATT&CK coverage mapping
  • Supporting blue team investigations with deep log analysis and quick-turnaround queries
  • Working with multiple data sources: firewalls, EDR, proxy, VPN, NetFlow, etc.

You’ll Fit If You Have

  • 1–3 years writing SIEM/EDR detection content
  • 1+ year in a SOC environment (Tier 2+ preferred)
  • Strong grasp of detection engineering and attacker methodology
  • Solid experience with ELK, Splunk, or similar SIEM platforms
  • Comfort pivoting through logs under pressure and building fast, accurate queries
  • Experience with threat modeling and mapping detections to MITRE ATT&CK
  • Bonus: You've worked with version control for detection rules, or done some detection-as-code
  • Certs like GCIA, GCIH, CEH, GNFA, GCFA
  • Familiarity with frameworks like Sigma or KQL
  • A side interest in threat hunting or malware behavior

What You’ll Impact

  • How quickly we detect and respond to real threats
  • The signal-to-noise ratio of our security stack
  • Our ability to spot emerging TTPs and adapt quickly

Why Join?

  • Work with a smart, collaborative cyber team that values creativity and curiosity
  • Make real contributions to global security operations
  • Flexible hybrid setup, no micromanaging — just impact
  • Opportunity to own detection content and make your mark in a high-impact space
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior SIEM Content Developer

ECS Resource Group

Remote

GBP 45,000 - 70,000

9 days ago

Part-Time Social Media Content Creator (Remote)

Apply4U | Job search & Recruitment Platform

Remote

GBP 60,000 - 80,000

Today
Be an early applicant

Part-Time Social Media Content Creator (Remote)

Apply4U | Job search & Recruitment Platform

Remote

GBP 60,000 - 80,000

Yesterday
Be an early applicant

Data & AI Video Content Developer

TN United Kingdom

Remote

GBP 40,000 - 70,000

2 days ago
Be an early applicant

Senior Content Developer (AI)

TN United Kingdom

Remote

GBP 40,000 - 80,000

11 days ago

Social media content creator - B2B tech

Canonical

City of Edinburgh

Remote

USD 30,000 - 55,000

5 days ago
Be an early applicant

Social media content creator - B2B tech

Canonical

Manchester

Remote

USD 30,000 - 60,000

5 days ago
Be an early applicant

Content Developer (Chemistry) - AI Trainer

DataAnnotation

Erith

Remote

GBP 60,000 - 80,000

Today
Be an early applicant

Content Developer - Math

DataAnnotation

Chester

Remote

GBP 60,000 - 80,000

3 days ago
Be an early applicant