This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
I'm looking for a hands-on SIEM Engineer to work on mission-critical Defence and National Intelligence systems. This is not a BAU SOC role. You’ll be owning SIEM capability end to end in some of the most secure environments in the UK. High trust, high autonomy technical role. Join a small number of engineers trusted with systems that genuinely matter. This is a great chance to use your SIEM skills in a highly secure defence environment.
Job Responsibility:
Owning and optimising Splunk ES and/or Elastic Security
Building high-fidelity, MITRE ATT&CK-aligned detections
Designing and maintaining SIEM pipelines (CIM / ECS)
Automating detection and response using CI/CD, SOAR and IaC
Ensuring SIEM platforms are resilient, scalable and performant
Owning SIEM capability end to end
Work on classified, real-world threats not theoretical use cases
Influence platform design, detection strategy and automation
Requirements:
Active UK DV clearance – essential
Proven, hands-on experience with Splunk ES and/or Elastic Security
Strong detection engineering background
Advanced SPL / KQL / EQL
Experience running SIEM at scale in high-security environments