About the Role
We are seeking an experienced Splunk SIEM Engineer to join a leading organisation within the Financial Services sector.
You will be responsible for designing, developing, administering, and enhancing enterprise SIEM capabilities while working across modern security technologies including Splunk Enterprise Security, Splunk Cloud, Microsoft Sentinel, and Cribl Stream.
This is an exciting opportunity to work within a large-scale enterprise environment, helping improve threat detection, security monitoring, automation, and incident response capabilities.
Essential Experience
- Bachelor's degree (minimum qualification).
- Strong experience administering and developing Splunk Enterprise.
- Extensive experience with Splunk Enterprise Security (ES), including:
- Administering, managing, and maintaining SIEM environments.
- Developing SIEM use cases and correlation searches.
- Strong understanding of Splunk Data Models.
- Hands-on experience with Splunk Cloud.
- Hands-on experience with Microsoft Sentinel.
- Experience with Cribl Stream, including log ingestion, data routing, transformation, parsing, and data normalisation.
- Experience working in enterprise Security Operations environments, including threat detection, incident response, and security event analysis.
- Experience with SOAR platforms, playbook development, and security automation.
- Good understanding of network security, including Firewalls, proxies, network architecture, and common attack vectors.
- Excellent technical documentation and communication skills.
Desirable Skills
- AWS and Azure cloud security.
- Containerised environments and SaaS security solutions.
- Python, PowerShell, SPL, KQL, and SQL.
- EDR, UBA, CASB, CSPM, vulnerability assessment, and threat intelligence platforms.
- CI/CD tools such as GitLab and Jenkins.
- Infrastructure as Code using Chef or Ansible.
- Knowledge of SOX, PCI-DSS, and GDPR.
- Incident response and digital forensics experience.
Preferred Certifications
- CISSP
- GCIH
- GCFA
- Splunk Certified Architect
- Microsoft Sentinel