Haystack
← Back to Jobs
Any
Technology

Security Engineer (SIEM integration) - 6 Month Fixed-Term Contract

Precise Placements LtdLondon🇬🇧United KingdomPosted 29 Jul 2026

Quick Overview

Work Type
Hybrid
Schedule
Any
Level
Mid Senior

Job Description

Security Engineer (SIEM integration) - 6 Month Fixed-Term Contract

We are a leading international professional services organisation with a strong global presence across Europe, the Americas, the Middle East and Asia. We provide specialist advisory services to multinational organisations, financial institutions and investment firms, operating within highly regulated environments.

We are seeking an experienced Security Engineer (SIEM integration) to join our Information Security Operations team on a 6-month fixed-term contract. This role will play a key part in enhancing and maturing our security monitoring and detection capabilities.

The Role

As a Security Engineer, you will focus on strengthening and optimising our Security Information and Event Management (SIEM) platform. You will be responsible for onboarding new log sources, improving data pipelines, developing advanced detection use cases, and supporting incident response activities.

This is an excellent opportunity for a security professional who enjoys building scalable, high-performing security monitoring environments and working in a collaborative, fast-paced setting.

You will report to the Information Security Operations Manager and work closely with the wider security team and internal stakeholders to improve the organisation's overall security posture.

Key Responsibilities

SIEM Engineering & Optimisation

  • Enhance and optimise the SIEM platform to improve performance, coverage, and detection accuracy

  • Assess SIEM architecture and recommend improvements across ingestion, parsing, correlation, and storage

  • Implement automation and orchestration (SOAR) to streamline security operations

Log Source Onboarding & Integration

  • Identify and onboard log sources across cloud, network, endpoint, identity, and application layers

  • Develop custom parsers, connectors, and ingestion workflows

  • Collaborate with internal teams and vendors to ensure high-quality telemetry

Detection Engineering

  • Design and implement detection use cases aligned to frameworks such as MITRE ATT&CK

  • Build and tune correlation rules, alerts, dashboards, and anomaly detections

  • Continuously improve detection quality and reduce false positives

SOC & Incident Response Support

  • Partner with SOC analysts to refine detection logic

  • Support investigations through advanced SIEM querying and data analysis

  • Provide subject matter expertise during complex security incidents

Documentation & Governance

  • Maintain clear documentation of SIEM architecture, data models, and detection logic

  • Ensure alignment with internal policies, compliance requirements, and industry standards

Skills & Experience

Technical Expertise

  • Strong hands-on experience with SIEM platforms (eg Splunk, Microsoft Sentinel, QRadar, Elastic, LogRhythm, ArcSight, Exabeam)

  • Knowledge of log formats (JSON, syslog, XML, CEF) and ingestion methods (APIs, agents, Kafka, Event Hubs)

  • Experience in detection engineering, threat modelling, and attacker behaviour analysis

  • Familiarity with SOAR tools and automation workflows

Security Knowledge

  • Understanding of networks, Windows/Linux systems, cloud platforms (Azure, AWS, GCP), identity systems, and endpoint security tools

  • Knowledge of frameworks such as MITRE ATT&CK and threat hunting methodologies

Essential Requirements

  • Degree (or equivalent experience) in a computing or related discipline

  • Proven experience across IT infrastructure and information security

  • Relevant certifications (eg GIAC, CISSP, SSCP, Microsoft SC-200/SC-100, CompTIA Security certifications)

  • Strong Scripting skills (Python, PowerShell, or similar)

  • Excellent communication skills with the ability to engage stakeholders at all levels

  • Proactive, self-starting approach with strong problem-solving ability

Desirable Experience

  • Data Loss Prevention (DLP)

  • Network security and secure remote access solutions

  • Cloud and software-defined environments (SaaS, IaaS, PaaS, DaaS)

  • Cyber threat intelligence and open-source intelligence tools

  • Disaster recovery and business continuity planning

  • Knowledge of data privacy regulations

Additional Information

  • Some out-of-hours work may be required for planned changes or security incidents

  • Opportunity to contribute to strategic security initiatives and service improvements

If you are a motivated Security Engineer looking to make a tangible impact within a global, highly regulated environment, we would love to hear from you.

Skills

GCP
AWS
Splunk
Azure
Kafka
PowerShell
Python

Similar jobs