Rate: Up to £700/day Insire IR35
Clearance: Active SC Clearance (Essential)
Location: Hybrid, Hampshire
Contract: Initial 6 Months with potential extension
Specialist SIEM Engineer needed to develop, optimise and automate SSE's Microsoft Sentinel platform, supporting security monitoring, detection engineering and Project Amur/ECAF compliance.
Scope
- Onboard and integrate log sources into Sentinel; build custom parsers and data transformations
- Design and optimise KQL queries; build and tune analytic rules and detection logic
- Develop Logic Apps/SOAR workflows to automate response
- Implement CI/CD pipelines (Azure DevOps/Git) for SIEM content deployment
- Automate deployment/config across environments; tune detections to reduce false positives
Key Skills
- Active SC Clearance (Essential)
- Strong Microsoft Sentinel engineering, administration and optimisation experience
- Log source onboarding, custom parsers and data normalisation
- Advanced KQL development and optimisation
- Analytic rule/detection logic design and tuning
- Logic Apps, Playbooks and SOAR automation
- Azure DevOps/Git CI/CD pipeline implementation
- Strong grounding in security monitoring, incident response and threat hunting
- Strong troubleshooting and root cause analysis skills
Desirable
- SANS SEC503 – Network Monitoring and Threat Detection
