Work closely with security analysts and engineers to detect and address security gaps by implementing automation workflows that enhance security operations. Evaluate and enhance CSOC workflows and processes by integrating automation through SOAR tools and technologies. Create and implement custom scripts to automate current detection and response workflows. Requirements: Experience More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Defence
improving the government's ability to detect and respond to cyber threats across multiple portfolios. You'll work alongside the SIEM Product Owner and CSOC teams to define and deliver architectural and engineering enhancements using Splunk SaaS and related technologies. Key Responsibilities Produce and maintain architecture diagrams, high- and low … level design documentation Lead configuration of Splunk and associated infrastructure (AWS EC2, S3, SQS, etc.) Drive use case development aligned with CSOC and MITRE ATT&CK framework Attend and represent the project at key technical forums (ADF, TDA, workshops) Deliver improvements to SIEM architecture, use cases, automation, and data enrichment … Essential Skills & Experience Strong experience in Splunk SaaS as a lead engineer and/or architect Deep understanding of SIEM Engineering & Architecture , particularly in CSOC environments Demonstrated experience leading end-to-end SIEM improvement initiatives Proven ability to define and implement change within complex cyber environments Excellent documentation, communication, and More ❯
main responsibilities will be to: Produce Architecture diagrams, high level and low-level design documents. Configuration of Splunk with use cases in line with CSOC standards. Configuration of Splunk as part of onboarding CNI and all other systems. Configuration of all infrastructure including AWS - EC2, S3 buckets, SQS queues etc. … of delivery lifecycle experience for improvements to Splunk SaaS. Experience of defining improvements within Cyber departments, particularly, SIEM improvements within CyberSecurityOperationsCentre (CSOC) functions that result in an increase in SIEM Maturity Levels. Good communication, reporting, documentation and presentational skills. AWS Infrastructure skills for the configuration of EC2 More ❯
main responsibilities will be to: * Produce Architecture diagrams, high level and low-level design documents. * Configuration of Splunk with use cases in line with CSOC standards. * Configuration of Splunk as part of onboarding CNI and all other systems. * Configuration of all infrastructure including AWS - EC2, S3 buckets, SQS queues etc. … of delivery lifecycle experience for improvements to Splunk SaaS. * Experience of defining improvements within Cyber departments, particularly, SIEM improvements within CyberSecurityOperationsCentre (CSOC) functions that result in an increase in SIEM Maturity Levels. * Good communication, reporting, documentation and presentational skills. * AWS Infrastructure skills for the configuration of EC2 More ❯
South London, London, United Kingdom Hybrid / WFH Options
Summer Browning Associates
main responsibilities will be to: * Produce Architecture diagrams, high level and low-level design documents. * Configuration of Splunk with use cases in line with CSOC standards. * Configuration of Splunk as part of onboarding CNI and all other systems. * Configuration of all infrastructure including AWS - EC2, S3 buckets, SQS queues etc. … of delivery lifecycle experience for improvements to Splunk SaaS. * Experience of defining improvements within Cyber departments, particularly, SIEM improvements within CyberSecurityOperationsCentre (CSOC) functions that result in an increase in SIEM Maturity Levels. * Good communication, reporting, documentation and presentational skills. * AWS Infrastructure skills for the configuration of EC2 More ❯
strong experience in Splunk. Responsibilities: Produce Architecture diagrams, high level and low level design documents. Configuration of Splunk with use cases in line with CSOC standards. Configuration of Splunk as part of onboarding CNI and all other systems Configuration of all infrastructure including AWS - EC2, S3 buckets, SQA queues etc. … end experience of the delivery lifecycle experience for improvements Experience of defining improvements within Cyber departments, particularly, SIEM improvements within CyberSecurityOperationsCentre (CSOC) functions that result in an increase in SIEM Maturity Levels. Experience of the lifecycle of SIEM delivery, including convergence from other SIEMs. Splunk Architect - London More ❯
producing architecture diagrams, high level and low-level design documents. You will also be able to configure Splunk with use cases in line with CSOC standards and also configuration of Splunk as part of onboarding CNI and all other systems. Configuration of all infrastructure including AWS - EC2, S3 buckets, SQS … to Splunk SaaS is also essential. You must have experience of defining improvements within Cyber departments, particularly, SIEM improvements within CyberSecurityOperationsCentre (CSOC) functions that result in an increase in SIEM Maturity Levels. Please apply ASAP to discuss further. More ❯