SIEM Engineer – Sentinel – Reading
Inside IR35 Active SC Clearance – must have used in the last 12 Months
Remote working
6 Months
Day rate up to £700
SIEM Engineer to come on board to be Responsible for onboarding and integrating security log sources into Microsoft Sentinel, ensuring reliable and comprehensive security telemetry.
Develop custom parsers and data transformations to normalise and enrich ingested data, and design and optimise KQL queries to support effective threat detection, monitoring and security investigations.
Key skills and responsibilities
- Integrate and onboard log sources into Microsoft Sentinel, ensuring reliable security telemetry.
- Develop custom parsers, data transformations and KQL queries for threat detection and investigation.
- Create and maintain analytic rules and detection logic aligned to emerging threats and business requirements.
- Develop Logic Apps and SOAR workflows to automate security response.
- Implement CI/CD pipelines using Azure DevOps/Git for controlled SIEM content deployment.
- Automate SIEM configuration and deployments across environments.
- Continuously tune and optimise detections to improve accuracy and reduce false positives.
- Experience with LogRhythm, Check Point firewalls and SIEM logging platforms.
- SEC503 / SANS certification or training would be highly desirable.