Negotiable
Undetermined
Remote
Guildford , UK
Summary: The Senior SIEM Engineer role involves providing technical expertise in Security Information and Event Management (SIEM) systems, specifically focusing on Microsoft Sentinel and Kusto Query Language (KQL). This position is primarily remote with occasional visits to the Guildford office and is offered as a temporary contract for over six months. The successful candidate will be responsible for developing detection rules, ensuring platform reliability, and onboarding log sources into Sentinel.
Key Responsibilities:
- Able to develop and maintain high-fidelity detection rules using Kusto Query Language
- Able to utilize KQL for detection engineering, analytics, and threat-hunting.
- Act as the technical SME for Microsoft Sentinel
- Hands-on experience including analytics rules, connectors, and workbooks.
- Ensure platform reliability and data quality.
- Coordinate the end-to-end onboarding of log sources into Sentinel.
Key Skills:
- Expert in KQL
- Technical SME for Sentinel set up
- Strong understanding of cloud and on premises logging (Windows, Linux, application, DB, identity).
- Experience onboarding data using AMA, DCRs, syslog/CEF, and Event Hub integrations.
- Comfortable using AI assisted tooling (eg, Copilot for Security) to enhance productivity.
Salary (Rate): undetermined
City: Guildford
Country: UK
Working Arrangements: remote
IR35 Status: undetermined
Seniority Level: undetermined
Industry: IT
Detailed Description From Employer:
Senior SIEM engineer
Our client, a leading global supplier for IT services, requires Senior SIEM engineer/Technical SME.
This is a remote role with occasional visits to the Guildford office.
This is a 6+ month temporary contract to start ASAP
Day rate: Competitive Market rate
Key Responsibilities
KQL: Expert Level
- Able to develop and maintain high-fidelity detection rules using Kusto Query Language
- Able to utilize KQL for detection engineering, analytics, and threat-hunting.
Microsoft Sentinel:
- Act as the technical SME
- Hands-on experience including analytics rules, connectors, and workbooks.
- Ensure platform reliability and data quality.
- Coordinate the end-to-end onboarding of log sources into Sentinel.
Key Requirements
- Expert in KQL
- Technical SME for Sentinel set up
- Strong understanding of cloud and on premises logging (Windows, Linux, application, DB, identity).
- Experience onboarding data using AMA, DCRs, syslog/CEF, and Event Hub integrations.
- Comfortable using AI assisted tooling (eg, Copilot for Security) to enhance productivity.
Due to the volume of applications received, unfortunately we cannot respond to everyone.
If you do not hear back from us within 7 days of sending your application, please assume that you have not been successful on this occasion.