
Security Operations Platform Enablement Engineer
- London
- Permanent
- Full-time
- Support the delivery of Data Engineering and Security Automation services in day-to-day operations
- Work with Security Operations leadership, Data Engineering and Security Automation resources to design and deliver strategic projects and solutions
- Support 24/7/365 Security Operations teams, including Incident Response personnel throughout the course of an event if required
- Work closely with Security Operation Centre analysts to ensure end-user requirements are replicated in the functionality of security technologies
- Take ownership of local requirements and integrate them into the global security services, coordinating efforts between regional stakeholders and other engineering functions
- Lead and mentor junior resources across the global team
- Experience in Security Engineering, consisting of a minimum of 2+ years’ recent experience in SIEM Engineering or similar engineering discipline
- Experience working in complex enterprises and global organizations. Insurance and financial services experience a plus.
- Deep understanding of standard security controls and frameworks in enterprise environments
- Experienced in task management technologies (Jira, ServiceNow, Confluence) desirable
- Strong Information Technology technical skills, with experience in coordination of technical teams and individual resources
- Proven ability to design and implement ingestion and transformation pipelines across modern data platforms
- Experience with SOAR solutions desirable
- Comfortable working in high pressure environments often outside of working hours throughout the course of an event
- An understanding of cyber security operations processes, procedures, guidelines and solutions, including practical experience of cyber kill chain principles
- Strong understanding of Windows, UNIX, and Linux operating systems, Cloud infrastructure, networking, malware defences, and perimeter controls.
- Familiarity with CrowdStrike NGSIEM data connectors, pipelines and parsers preferable
- Exposure to log aggregation platforms for data normalization and routing (eg Cribl, Apache Kafka) desirable
- Bachelor’s degree or equivalent practical experience is preferred.
- Experience with security monitoring, event and anomaly analysis and intrusion detection/ prevention techniques.
- CISSP desirable
- Strong analytical and problem-solving skills with the ability to troubleshoot complex technical issues
- Excellent communication skills and the ability to collaborate effectively with cross-functional teams
- Proactive and self-motivated with the ability to work independently and manage multiple tasks simultaneously