
SecOps Engineer
- Gloucester
- £60,000 per year
- Permanent
- Full-time
- Configure the EDF managed SIEM correctly with appropriate data sources and keep the design collateral up to date.
- Build the SIEM alerting rule set that meets the requirement to alert SOC analysts to events of interest
- Ensure that the SIEM services operated by our partners are assured and integrate appropriately with EDF systems
- Work with the Cyber Defence team leads to inform the tactical roadmap of SIEM products and services
- Work with IT teams to optimise logging from their systems to the SIEM with sufficient event data to support the alerting requirements.
- Align the SIEM use cases to a common framework (e.g. Mitre ATT&CK) to demonstrate coverage to the business.
- Proven experience in the design, configuration, and use of SIEM and SOAR platforms.
- Strong skills in collecting and analyzing data from multiple logging sources, with the ability to develop effective alerting and query rules.
- Solid understanding of integrating common security technologies (such as EDR, IPS, firewalls, and audit systems) into SOC and SIEM environments.
- Experience deploying cloud platforms using Terraform and working with CI/CD pipelines.
- Ability to communicate clearly with business stakeholders, offering meaningful insights into the configuration, performance, and value of the security monitoring systems.
- A working knowledge of cyber incident response, associated toolsets, and their capabilities.
- Familiarity with the NIST Cybersecurity Framework, particularly its five core functions: Identify, Protect, Detect, Respond, and Recover.
- Comfortable managing multiple priorities in a fast-paced environment, working effectively with both technical and non-technical stakeholders in person and remotely.