Hays Technology

Hays Technology

Knutsford, North West

Splunk SIEM Engineer

Contract£? - ? per yeargisterenUnited Kingdom
IT

Job Description

Salary: £? - ? per year

Requirements:
  • Proven experience with Splunk Enterprise Security, including administration, management, and maintenance of SIEM platforms.
  • Strong experience in SIEM architecture, including data models, correlation rules, and administrative functions.
  • Demonstrable experience developing use cases and correlation searches in Splunk Enterprise.
  • Hands-on knowledge of Splunk Cloud.
  • Hands-on experience with Microsoft Sentinel.
  • Evidence of Splunk Enterprise administration and development skills.
  • Strong analytical skills in threat detection, incident response, and security event analysis, ideally in large enterprise environments with 10,000+ endpoints.
  • Hands-on experience with log ingestion, data routing, and transformation tools such as Cribl Stream.
  • Understanding of data normalisation and parsing in Splunk Enterprise.
  • Experience with Security Orchestration and Automation platforms, playbook development, and automated response workflows.
  • Working knowledge of network architectures, firewalls, proxies, and common attack vectors.
  • Excellent technical writing and communication skills, with the ability to produce runbooks and procedures.
  • Proficiency with CI/CD tools such as GitLab and Jenkins.
  • Proficiency in Python, PowerShell, KQL, SPL, and SQL.
  • Ability to work in the UK with UK residency required; no sponsorship available.
Responsibilities:
  • We design, develop, and improve software using engineering methodologies to deliver business, platform, and technology capabilities.
  • We administer, manage, and maintain SIEM platforms and related security tooling.
  • We develop use cases and correlation searches for Splunk Enterprise Security.
  • We work with data models, log ingestion, routing, transformation, normalisation, and parsing across security data pipelines.
  • We support threat detection, incident response, and security event analysis.
  • We develop automation workflows, playbooks, and security orchestration responses for incident management.
  • We create runbooks, procedures, and technical documentation for diverse audiences.
  • We troubleshoot network-security-related issues across firewalls, proxies, and attack vectors.
  • We collaborate across teams in a hybrid working model based in Cheshire, with on-site attendance three days per week and two days from home.
Technologies:
  • CI/CD
  • Cloud
  • GitLab
  • Incident Management
  • Support
  • Jenkins
  • Network
  • PowerShell
  • Python
  • SQL
  • Security
  • Splunk
  • AWS
  • Ansible
  • Architect
  • Azure
  • DevOps

More:

We are working with a global leader in consulting, technology services, and digital transformation, committed to delivering positive change through technology and human collaboration. This Splunk SIEM Engineer role is based in Cheshire with hybrid working in the UK, typically three days on site and two from home, with potentially more flexibility once established. Please note that only candidates who are resident in the UK, have the right to work in the UK, and meet the outlined criteria will be considered, as no sponsorship is available.

last updated 31 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Hays Technology

Hays Technology

Hays Technology

Knutsford

IT

Skills & Technologies

PythonAWSAzureGitCI/CDJenkinsAIDevOpsUI

Inferred from job description

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom