- Company Name
- Methods
- Job Title
- Cyber Security Engineer SoC/SIEM (Contract)
- Job Description
-
**Job title:** Cyber Security Engineer SoC/SIEM (Contract)
**Role Summary:**
A contract Cyber Security Engineer responsible for designing, implementing, and operating Security Operations Center (SOC) and Security Information and Event Management (SIEM) solutions with the Elastic Stack, Azure Sentinel, and related tools. The role focuses on log ingestion, detection engineering, SOC policy development, incident response support, and client-facing communication.
**Expectations:**
- Contract basis (duration to be decided), requiring ongoing performance and successful project delivery.
- Must hold active Security Clearance (SC and/or DV) or be eligible for DV.
- Works in a multidisciplinary environment with government and private sector stakeholders.
**Key Responsibilities:**
- Build, configure, and optimise Logstash pipelines and rsyslog setups for diverse log sources.
- Develop and tune detection rules (ESQL, EQL, Lucene) and create investigation guides aligned with MITRE ATT&CK.
- Design, document, and improve SOC processes, alert tune‑ups, and SIEM governance.
- Support incident response lifecycle: case triage, evidence handling, escalation, and forensic data support.
- Produce formal documentation following Defence Writing principles and JSP standards.
- Communicate findings, recommendations, and status updates to internal teams and external clients.
- Integrate additional SIEM/SOAR tools (TheHive, MISP, Cortex) and threat intelligence platforms when required.
**Required Skills:**
- Advanced Elastic Stack expertise: Kibana dashboards, Logstash, Elasticsearch, anomaly detection, timeline analysis.
- Linux administration, Bash and Python scripting for SIEM operations and log parsing.
- Security Operations experience, SOC maturity, and incident response.
- Knowledge of security frameworks (MITRE ATT&CK, NIST CSF, ISO 27001) and mapping TTPs to detection rules.
- Experience with Azure Sentinel and cloud SIEM architecture.
- Familiarity with SOAR tools, threat intelligence feeds, and vulnerability management platforms.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Cyber Security, or related field (preferred).
- Elastic Certified Analyst (mandatory).
- Elastic Certified Engineer, CISSP, CEH, or equivalent security certifications (a plus).
- Must possess or be willing to obtain active SC or DV clearance.
Great malvern, United kingdom
On site
14-11-2025