Splunk SIEM Engineer
Job Description
Splunk SIEM Engineer
\nLocation: Manchester ( 3 days on site )
\nContract Duration: Until 30 November 2026
\nIR35 Status: Inside IR35
\nDay Rate:500-550
\nStart Date:11/08/2026
About the Role\nWe are seeking an experienced Splunk SIEM Engineer to join a leading organisation within the Financial Services sector. You will be responsible for designing, developing, administering, and enhancing enterprise SIEM capabilities while working across modern security technologies including Splunk Enterprise Security, Splunk Cloud, Microsoft Sentinel, and Cribl Stream.
\nThis is an exciting opportunity to work within a large-scale enterprise environment, helping improve threat detection, security monitoring, automation, and incident response capabilities.
Essential Experience\n\n
\n
- \n
- Bachelor's degree (minimum qualification). \n
- Strong experience administering and developing Splunk Enterprise. \n
- Extensive experience with Splunk Enterprise Security (ES), including: \n
- Administering, managing, and maintaining SIEM environments. \n
- Developing SIEM use cases and correlation searches. \n
- Strong understanding of Splunk Data Models. \n
- Hands-on experience with Splunk Cloud. \n
- Hands-on experience with Microsoft Sentinel. \n
- Experience with Cribl Stream, including log ingestion, data routing, transformation, parsing, and data normalisation. \n
- Experience working in enterprise Security Operations environments, including threat detection, incident response, and security event analysis. \n
- Experience with SOAR platforms, playbook development, and security automation. \n
- Good understanding of network security, including Firewalls, proxies, network architecture, and common attack vectors. \n
- Excellent technical documentation and communication skills. \n
\nDesirable Skills\n
\n
\n
- \n
- AWS and Azure cloud security. \n
- Containerised environments and SaaS security solutions. \n
- Python, PowerShell, SPL, KQL, and SQL. \n
- EDR, UBA, CASB, CSPM, vulnerability assessment, and threat intelligence platforms. \n
- CI/CD tools such as GitLab and Jenkins. \n
- Infrastructure as Code using Chef or Ansible. \n
- Knowledge of SOX, PCI-DSS, and GDPR. \n
- Incident response and digital forensics experience. \n
\nPreferred Certifications\n
\n
\n
- \n
- CISSP \n
- GCIH \n
- GCFA \n
- Splunk Certified Architect \n
- Microsoft Sentinel \n
\nInterested?\n
If this opportunity is of interest, we'd love to hear from you.
\nIf this role isn't quite the right fit but you know someone who may be suitable, please feel free to share this opportunity with them.
