SIEM Engineer (Security Information and Event Management) - SC CLEARED - Wokingham and Remote - 12 months
One of our Blue Chip Clients is urgently looking for a SIEM Engineer (Security Information and Event Management).
CANDIDATES MUST HOLD ACTIVE SC CLEARANCE
Role Description
- SIEM Deployment & Management – Set up, configure, and maintain SIEM tools like Sentinel and Elastic.
- EDR deployment, configuration & management – Experience with tools such as Tanium, Trellix, FireEye, Defender, and Elastic EDR.
- Threat Detection & Analysis – Monitor security logs, detect anomalies, and investigate potential threats.
- Configure Syslog Servers – Maintain and configure syslog feeds.
- Log ingestion creation for Sentinel – Deploy out‑of‑the‑box integrations and develop custom integrations for various log source types.
- Collaboration – Work with IT and security teams to improve overall cybersecurity posture.
Required Skills & Qualifications
- Technical expertise – Strong knowledge and experience in security engineering with SIEM & EDR platforms, network security, and understanding of cybersecurity frameworks.
- Certifications – CISSP, CEH, GIAC, vendor‑specific SIEM certifications, AZ‑500, SC‑100, etc.
- Programming & Scripting – Familiarity with Python, PowerShell, KQL (Kusto Query Language), KQL (Kibana Query Language), or other scripting languages.
- Analytical thinking & problem solving – Ability to analyze large datasets and identify threats, mitigations, and misconfigurations.
- Communication skills – Ability to document findings and communicate effectively with stakeholders.
Please send CV for full details and immediate interviews. We are a preferred supplier to the client.