Hays Technology
Splunk SIEM Engineer
Job Description
Salary: £? - ? per year
Requirements:- Proven experience with Splunk Enterprise Security, including administration, management, and maintenance of SIEM platforms.
- Strong experience in SIEM architecture, including data models, correlation rules, and administrative functions.
- Demonstrable experience developing use cases and correlation searches in Splunk Enterprise.
- Hands-on knowledge of Splunk Cloud.
- Hands-on experience with Microsoft Sentinel.
- Evidence of Splunk Enterprise administration and development skills.
- Strong analytical skills in threat detection, incident response, and security event analysis, ideally in large enterprise environments with 10,000+ endpoints.
- Hands-on experience with log ingestion, data routing, and transformation tools such as Cribl Stream.
- Understanding of data normalisation and parsing in Splunk Enterprise.
- Experience with Security Orchestration and Automation platforms, playbook development, and automated response workflows.
- Working knowledge of network architectures, firewalls, proxies, and common attack vectors.
- Excellent technical writing and communication skills, with the ability to produce runbooks and procedures.
- Proficiency with CI/CD tools such as GitLab and Jenkins.
- Proficiency in Python, PowerShell, KQL, SPL, and SQL.
- Ability to work in the UK with UK residency required; no sponsorship available.
- We design, develop, and improve software using engineering methodologies to deliver business, platform, and technology capabilities.
- We administer, manage, and maintain SIEM platforms and related security tooling.
- We develop use cases and correlation searches for Splunk Enterprise Security.
- We work with data models, log ingestion, routing, transformation, normalisation, and parsing across security data pipelines.
- We support threat detection, incident response, and security event analysis.
- We develop automation workflows, playbooks, and security orchestration responses for incident management.
- We create runbooks, procedures, and technical documentation for diverse audiences.
- We troubleshoot network-security-related issues across firewalls, proxies, and attack vectors.
- We collaborate across teams in a hybrid working model based in Cheshire, with on-site attendance three days per week and two days from home.
- CI/CD
- Cloud
- GitLab
- Incident Management
- Support
- Jenkins
- Network
- PowerShell
- Python
- SQL
- Security
- Splunk
- AWS
- Ansible
- Architect
- Azure
- DevOps
More:
We are working with a global leader in consulting, technology services, and digital transformation, committed to delivering positive change through technology and human collaboration. This Splunk SIEM Engineer role is based in Cheshire with hybrid working in the UK, typically three days on site and two from home, with potentially more flexibility once established. Please note that only candidates who are resident in the UK, have the right to work in the UK, and meet the outlined criteria will be considered, as no sponsorship is available.
last updated 31 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Hays Technology
Hays Technology
Knutsford
IT
Skills & Technologies
Inferred from job description