Security Consultant - SIEM Engineer

Job City:  Guildford
Professional Area:  Security
Job Req ID:  123103

 

Location(s): UK, Europe & Africa : UK : Guildford || UK, Europe & Africa : UK : Frimley 

 

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.

Job Title: Security Consultant - SIEM Engineer

 

Location: Guildford, Frimley - We offer a range of hybrid and flexible working arrangements – please speak to your recruiter about the options for this particular role

 

Who we are

 

Join BAE Systems and you’ll be part of something bigger. As a valued member of our global colleague network, you’ll bring your unique skills and perspectives to help pioneer progress and protect what matters most. You’ll be trusted to play your part in delivering the advanced, technology-led defence, aerospace and security solutions of tomorrow - shaping a safer future, for all of us.

 

From the depths of the ocean, to the far reaches of space - there’s no limit to where a career at BAE Systems could take you.

 

Role Description 

 

BAE Systems have been contracted to undertake the design and build of a dedicated Security Operations Centre (SOC) to support the cyber defence of a major international defence programme.  The information, systems and networks to be protected will be a mix of Microsoft Cloud services and on-premises data centres straddling multiple regions and classification levels.

We are looking for a talented and enthusiastic individual with excellent technical and client-facing skills, to act as an SIEM Engineer who will support the design, configuration and maintenance of a wide range of security tools.  This is mid level role and the individual will be expected to work across a variety of technologies such as Splunk and Sentinel SIEM, Nessus Vulnerability management, Microsoft XDR and other as appropriate.

The role will range from advising on design, deploying and configuring new solutions, assessing existing deployments and client capabilities to make improvements and improve overall maturity.  This role is situated within our Defence Business unit and requires a minimum of SC clearance, ideally DV clearance. The position is expected to work from company offices in the UK with some time on client sites in UK and occasional travel to Europe and Asia. 

  • Design, deploy and configuration of SIEM applications (e.g. SPLUNK enterprise, enterprise security, Splunk SOAR and UBA, Microsoft Sentinnel, Elastic, Microsoft XDR and other) including:
    • Specify infrastructure requirements (RAM, Disk, CPU, Network bandwidth) for SIEM applications
    • Integration of SIEM application with identity management solutions.
    • Integration of SIEM applications with Vulnerability Management, and Asset and Configuration Management systems to enrich efficacy of the solution.
    • Integration of SIEM application with Cyber Threat Intelligence and Case Management solutions.
    • Design, implement and manage log collection and onboarding activities to SIEM.
    • Identify initial set of use cases & playbooks for detection and automation content and required development, deployment, testing and release.
    • Support deployment of SIEM application to both cloud hosting and containers, and OnPrem hosted VM’s and containers
  • Oversee deployment / implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
  • Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
  • The role is a cyber technical specialist with deep knowledge of the Cyber Monitoring technologies and cyber threat tools, tactics, techniques and procedures.
  • Develop test procedures to test solutions meet functional and non-functional requirements
  • Generalist Technical SME to support deployment and configuration of various tools including Jira and Cribl

 

Core Duties 

 

  

  • Knowledge and experience of  design, build, deployment and operation of SIEM/SOAR tools (Splunk and Sentinel at a minimum) and other appropriate tooling e.g. SOAR, Threat Intelligence, traffic analysis tools etc. to identify signs of an intrusion, and advise where new/improved tooling could enhance the SOC operation
  • Experience deploying and configuring SIEM applications (e.g. SPLUNK and/ or MS Sentinnel) in a performant manner on cloud and / or OnPrem to support high data rates
  • Proven delivery and experience leading conducting onboarding activities onto a SIEM
  • Strong knowledge of how Azure and AWS security functions work as security controls as well as detection tools to protect large cloud estates; Produce content and playbooks on Sentinel and Splunk to detect security breaches and recognise the importance of threat led Use Cases.
  • Deep knowledge and experience of Enterprise ICT.
  • Working with a range of security tooling/technology.
  • Strong understanding of security architecture, in particular networking.
  • Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
  • Understand TCP/IP component layers to identify normal and abnormal traffic.

 

 

The Team

 

We work hard and often go the extra mile, but we recognise people’s efforts and that everyone has a life outside of work. We encourage people to speak up if they want to rotate to a new project.

 

Why BAE Systems

This is a place where you’ll be able to make a real difference. You’ll be part of an inclusive culture which values diversity, rewards integrity and merit, and where you’ll be empowered to fulfil your potential. We welcome candidates from all backgrounds and particularly from sections of the community who are currently under-represented within our industry including women, ethnic minorities, people with disabilities and LGBTQ+ individuals

We also want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments.

Please be aware that many roles at BAE Systems are subject to both security and export control restrictions. These restrictions such as your nationality, any nationalities which you previously may have held and your place of birth can restrict the roles you are able to perform within the organisation.

All applicants must as a minimum achieve Baseline Personnel Security Standard. Many roles also require higher levels of National Security Vetting where applicants must typically have 5 to 10 years

Life at BAE Systems Digital Intelligence 

We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day.

By embracing technology, we can interact, collaborate and create together, even when we’re working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being.

Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds – the best and brightest minds – can work together to achieve excellence and realise individual and organisational potential.

Job Title:  Security Consultant - SIEM Engineer

Job City:  Guildford
Professional Area:  Security
Job Req ID:  123103