- Company Name
- Harvey Nash
- Job Title
- Senior Sentinel Engineer (SIEM)
- Job Description
-
**Job Title**
Senior Sentinel Engineer (SIEM)
**Role Summary**
Lead the management and enhancement of a client’s SIEM environment, focusing on log source integration, analytic rule development, automated triage and remediation, and cross‑platform orchestration. Requires SOC leadership, advanced SSO/Automation, and SC clearance.
**Expactations**
- Deliver on‑time SIEM onboarding, rule creation, and automation projects.
- Drive continuous improvement of detection efficacy and response workflows.
- Collaborate with security, IT, and business stakeholders to align SIEM priorities.
- Maintain high‑level security posture in a scalable, cloud‑centric environment.
**Key Responsibilities**
1. Onboard and configure diverse log sources (identity, network, system, data, application, cloud).
2. Design, develop, and maintain analytic queries (KQL, Splunk, Azure Sentinel).
3. Build SOAR playbooks in Azure Sentinel / LogRhythm for automated triage and remediation.
4. Integrate SIEM outputs with incident‑management, ticketing, and threat‑intel platforms.
5. Lead, mentor, and coordinate a SIEM team; manage stakeholder expectations.
6. Conduct regular performance reviews, tuning, and reporting of SIEM metrics.
**Required Skills**
- Deep expertise in SIEM platforms (Azure Sentinel, LogRhythm, Sentinel).
- Strong command of KQL, PowerShell, Python, and scripting for log analysis.
- Proven experience with SOAR tools and automated playbooks.
- Understanding of identity, network, system, data, application, and cloud security logs.
- Leadership and collaboration with cross‑functional stakeholders.
**Required Education & Certifications**
- BSc or equivalent in Computer Science, Cybersecurity, or related field.
- Industry certifications such as Microsoft Certified: Azure Security Engineer Associate, Sec+ or equivalent.
- Current Security Clearance (SC Level).