Search

Splunk SIEM Engineer

Posted: 30/07/26
Recruiter:Hays Technology
Reference:3146793195
Type:Contract
Disciplines: Systems Engineer
Salary:£500 - £638 Daily Inside IR35
Location:Knutsford, Cheshire
Description:

We are working with a client who is a global leader in consulting, technology services, and digital transformation, committed to delivering positive change through technology and human collaboration. They are looking for a Splunk SIEM Engineer to design, develop and improve software, utilising various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues.

You will need to demonstrate your Multi-Platform SIEM Expertise: you need proven experience with Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with log ingestion, data routing, and transformation using tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation: Excellent technical writing and communication skills to create runbooks, procedures, and translate complex security concepts for diverse audiences.

In order to apply, you must be able to evidence skills in Splunk Enterprise Admin and development. You will be proficient in Splunk Enterprise Security (SIEM) - administering, managing, and maintaining SIEM. Experienced in developing use cases/correlation searches. You will be proficient in data models. Have hands-on knowledge and understanding of Splunk Cloud. Hands-on experience of Microsoft Sentinel. Hands-on CI/CD tools like Gitlab, Jenkins etc. Proficiency in Cribl Stream is expected.
Awareness/experience of the following is an advantage - Cloud Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerised environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja. Extended Security Stack: Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms. Infrastructure as Code: Experience with Chef, Ansible, Jenkins, GitLab CI/CD for automated security tool deployment and configuration management. Compliance & Governance: Knowledge of regulatory frameworks (SOX, PCI-DSS, GDPR) and hands-on incident response/forensics experience.

Please be clear that only candidates that meet the above criteria with the right to work and that are resident in the UK will be considered. No sponsorship is available.
This role will involve hybrid working here in the UK at a site based in Cheshire - expected on site 3 days per week and 2 from home. More flexibility may be offered once in situ in the contract.

Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)

Recruiting now