Job Search and Career Advice Platform

Enable job alerts via email!

SIEM Application Engineer

Experis - ManpowerGroup

Birmingham

Hybrid

GBP 80,000 - 100,000

Part time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading recruitment agency is seeking a SIEM Application Engineer in Birmingham or Manchester. You will optimise detection rules and support security operations by analysing alerts and refining detection logic. Ideal candidates have hands-on experience with Elastic Security, a strong grasp of alert tuning, and solid communication skills. This is a hybrid role with a competitive day rate.

Qualifications

  • Hands-on experience with Elastic Security / Elastic SIEM.
  • Strong understanding of detection logic, alert tuning and threat behaviours.
  • Strong written communication skills for reporting and documentation.

Responsibilities

  • Analyse alerts generated by Elastic Security and validate detection accuracy.
  • Tune and optimise existing Elastic SIEM detection rules.
  • Map detections to the MITRE ATT&CK framework and identify coverage gaps.
  • Produce detection reports, tuning documentation, and analysis summaries.
  • Collaborate with SOC analysts and security teams.

Skills

Hands‑on experience with Elastic Security
Strong understanding of detection logic
Familiarity with MITRE ATT&CK
Strong written communication skills

Tools

Kibana
Elasticsearch queries (EQL/KQL)
Job description

Role: SIEM Application Engineer

Location: Birmingham or Manchester or Ipswich (Hybrid)

Duration: 3 Months with possible extension

Day rate: £450 - £550 via Umbrella

Overview

We are looking for an SIEM Application Engineer to support our security operations by reviewing and optimising detections within our production Elastic Security platform. This role focuses solely on detection analysis, rule refinement, and reporting, rather than SIEM platform engineering or DevOps.

Key Responsibilities
  • Analyse alerts generated by Elastic Security and validate detection accuracy.
  • Tune and optimise existing Elastic SIEM detection rules to improve fidelity and reduce false positives.
  • Map detections to the MITRE ATT&CK framework and identify coverage gaps.
  • Produce clear detection reports, tuning documentation, and analysis summaries.
  • Collaborate with SOC analysts, incident responders, and security engineering teams.
Required Skills
  • Hands‑on experience with Elastic Security / Elastic SIEM, Kibana, and Elasticsearch queries (EQL/KQL).
  • Strong understanding of detection logic, alert tuning, and threat behaviours.
  • Familiarity with MITRE ATT&CK.
  • Strong written communication skills for reporting and documentation.
Nice to Have
  • Experience in SOC, detection engineering, or threat hunting.
  • Exposure to common log types (endpoint, network, cloud).
  • Security certifications (Elastic, Security+, CySA+, etc.).
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.