SIEM Security Engineer
Listed on 2026-09-19
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
Job Description
Job Title:
SIEM Security Engineer
Req
Job Function:
Cyber Security
Posting
Start Date:
03/09/2026
Posting End Date: 01/10/2026
Division:
Networks
Job Location:
G
-Birmingham-Three Snowhill
Advertised Salary:
Competitive with Great Benefits
Job Req
Posting Date: 3rd Sep 2026
Closing Date: 1st Oct 2026
Location:
Birmingham
The new Network SIEM is essential to BT’s network security, meeting TSA requirements and improving our CAF level. Your role as a SIEM Application Engineer in Security Engineering is to support the development, implementation, operation and support of BTs Strategic SIEM development. We are seeking a skilled SIEM Security Engineer with expertise in SIEM and Security logging and monitoring to join our dynamic team.
As a SIEM engineer, you will play a critical role in designing, developing, and maintaining the ingestion of our security information and event management (SIEM) system. Your focus will be on leveraging Elasticsearch and related technologies to enhance threat detection, incident response, and overall security posture.
The role is hybrid (3 days in office) & based in Birmingham
What you’ll be doingData Ingestion and Enrichment
- Collaborate with Security analysts and application teams to provide clear design for the security scope of data ingestion.
- Support the configuration of Elasticsearch pipelines for data ingestion from various sources, primarily from Kafka
- Enhance data enrichment by integrating threat intelligence feeds and contextual information.
- Ingest data from various networking equipment, servers, firewalls and security appliances across multiple vendors.
- Collaborate with security analysts and architects to design and implement SIEM solutions using Elasticsearch.
- Continuously improving threat detection capabilities by tuning and optimising existing use cases and retiring use cases no longer providing value.
- Designing, implementing and managing security detection use cases across a range of technologies to ensure timely alerting of security events and incidents to Security Operations staff.
- Monitor and manage the performance of the SIEM infrastructure.
- Contribute to security engineering projects, transitions, and transformations.
- Work closely with security operations and associated security incident response systems
- Stay informed about emerging threats and security best practices.
- Proven experience in SIEM Detection Engineering.
- Experience using cyber security technologies such as NGFW, SIEM, Proxies, IAM solutions
- Experience of tuning security detection use cases. Experience with log source onboarding and normalisation
- Strong analytical and troubleshooting skills with the ability to investigate complex security events.
- Understanding of MITRE ATT&CK and modern cyber threat techniques.
- Experience working with Security Operations and engineering stakeholders.
- Excellent technical documentation and communication skills.
- Bachelor’s/Master’s degree in Computer Science, Information Systems, Engineering, or other related fields 5+ years of engineering experience in delivering cybersecurity solutions
- Experience in key cyber technologies such as SIEM technologies (Elastic preferred), vulnerability management, access management and other commonly used Enterprise security controls. Ideally from both a development and operational perspective
- SIEM implementation and usage Experience of Elastic Stack (ELK)
- Knowledge of Offensive testing frameworks
- Knowledge of Linux, Windows and Network Administration
- Knowledge and experience of cloud services (public or private), Open Stack and K8S
- Cyber security qualifications
- Knowledge of Git and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).