Splunk SIEM Engineer

Experis

Knutsford

Hybrid

GBP 150,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Experis seeks a Splunk SIEM Engineer in Knutsford for a contract role running until 30 November 2026. Hybrid work with 3 days per week onsite.

The role focuses on designing, developing and improving SIEM capabilities using Splunk Enterprise Security and Microsoft Sentinel, with emphasis on data models, correlation rules and incident response in a large enterprise.

Qualifications

  • Bachelor's degree required.
  • Experience with Splunk ES, Microsoft Sentinel, and SIEM architecture.
  • Experience in large enterprise environments (10,000+ endpoints).
  • Hands-on log ingestion and data routing (Cribl) in Splunk.
  • SOAR platforms and automated response workflows.
  • Strong incident detection and response skills.
  • Excellent written and verbal communication; able to create runbooks.

Responsibilities

  • Design, develop and improve security software and SIEM capabilities.
  • Work on data models, correlation rules, and admin functions.
  • Manage threat detection, incident response and security event analysis.

Skills

Splunk ES
Microsoft Sentinel
SIEM architecture
Threat detection
Incident response
Data ingestion
Cribl
SOAR platforms
Playbooks
Automation workflows
Network security
Runbooks

Education

Bachelor's degree

Tools

Splunk
Cribl

Job description

Role Title: Splunk SIEM Engineer

Duration: contract to run until 30/11/2026

Location: Knutsford. Hybrid, 3 days per week onsite

Rate: up to £587.33 p/d Umbrella inside IR35

Role purpose / summary

Join us as Splunk SIEM Engineer where you must design, develop and improve software, utilizing various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues.

Responsibilities & Qualifications
  • Minimum Qualification - bachelor's degree
  • Multi‑Platform SIEM Expertise: Proven experience with Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions.
  • Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints).
  • Data Pipeline Management: Hands‑on experience with log ingestion, data routing, and transformation using tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise.
  • SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management.
  • Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise.
  • Communication & Documentation: Excellent technical writing and communication skills to create runbooks, procedures, and translate complex security concepts for diverse audiences.
Preferred Skills
  • Cloud Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerised environments, and SaaS‑based security solutions.
  • Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development.
  • Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja.
  • Extended Security Stack: Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms.
  • Infrastructure as Code: Experience with Chef, Ansible, Jenkins, GitLab CI/CD for automated security tool deployment and configuration management.
  • Compliance & Governance: Knowledge of regulatory frameworks (SOX, PCI‑DSS, GDPR) and hands‑on incident response/forensics experience.
Additional Information

All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Splunk SIEM Engineer
Splunk SIEM Engineer

Experis - ManpowerGroup • Knutsford

Hybrid
GBP 105,000 - 165,000
Splunk SIEM Engineer
Splunk SIEM Engineer

Undisclosed • Knutsford

On-site
Hybrid Splunk SIEM Engineer - Incident Response & SOAR
Hybrid Splunk SIEM Engineer - Incident Response & SOAR

Experis - ManpowerGroup • Knutsford

Hybrid
GBP 105,000 - 165,000
Splunk SIEM Engineer — Threat Detection & Automation
Splunk SIEM Engineer — Threat Detection & Automation

Undisclosed • Knutsford

On-site
Security Engineer
Security Engineer

Computappoint • Greater London

Hybrid
GBP 65,000 - 80,000
Hybrid work
Office in City of London
Splunk Admin
Splunk Admin

Gazelle Global • Manchester

Hybrid
GBP 55,000 - 75,000
Security Engineer (Site Reliability Engineering)
Security Engineer (Site Reliability Engineering)

Sanderson Government & Defence • Greater London

Hybrid
GBP 101,000 - 109,000
SOC Engineer - DV cleared
SOC Engineer - DV cleared

CBSbutler Holdings Limited • Hemel Hempstead

On-site
GBP 92,000 - 129,000
Splunk Engineer
Splunk Engineer

Adecco • Chester

On-site
GBP 61,000 - 101,000
Managing Security Engineer - DV cleared
Managing Security Engineer - DV cleared

CBSbutler Holdings Limited trading as CBSbutler • Hemel Hempstead

On-site
GBP 92,000 - 129,000