- Company Name
- Aberdeen
- Job Title
- Cyber Security Engineer
- Job Description
-
Job Title: Cyber Security Engineer
Role Summary:
Design, implement, and maintain next‑generation Security Information and Event Management (SIEM) and log‑management platforms across a cloud‑centric, global enterprise environment. Drive detection fidelity, threat visibility, and compliance for Security Data & Analytics, Security Automation, Incident Response, and Threat Detection domains.
Expectations:
- Deliver high‑quality SIEM solutions and log pipelines that satisfy SOC and compliance requirements.
- Collaborate cross‑functionally with SOC, IT, developers, and third‑party security vendors.
- Apply industry best practices and emerging technologies to evolve the engineering function.
- Maintain proactive security posture in Azure and other cloud services, ensuring seamless integration with monitoring and automation tools.
Key Responsibilities:
- Develop advanced detection rules, correlation searches, and playbooks for threat detection and response.
- Onboard, parse, and normalize log sources; design and maintain SIEM alerts and SOC‑supporting dashboards.
- Engineer log pipelines using Cribl, optimizing ingestion, filtering, routing, and replay.
- Architect scalable log archival, data rehydration, and compliance‑driven retention solutions.
- Leverage Azure security services (Defender XDR, Azure Defender, Monitor, AD) to implement monitoring, alerting, and automation across IaaS/PaaS/SaaS.
- Integrate Azure EventHubs, Log Analytics, and apply Kusto Query Language (KQL) and Splunk Processing Language (SPL) for data pipelines and detection engineering.
- Contribute to security architecture reviews, risk assessments, and security content CI/CD pipelines.
- Manage incident, change, and workflow integration with ITSM tools (Jira, ServiceNow).
Required Skills:
- Expertise in SIEM engineering, log‑management, and cloud security (Azure).
- Proficiency with Cribl, Azure native security services, KQL, SPL, Azure EventHubs, Log Analytics.
- Experience in microservices architecture, Azure Logic Apps, DevSecOps practices.
- Strong scripting capabilities (Python, PowerShell, or equivalent) for automation and API interaction.
- Familiarity with ITSM tools (Jira, ServiceNow).
- Solid understanding of CI/CD for security content and configuration management.
- Ability to work effectively in globally dispersed teams.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Cyber Security, or related field (or equivalent professional experience).
- Industry certifications: one or more of SC‑200, SC‑100, AZ‑500, Certified Splunk Admin/Architect, PCSAE, CISSP, CEH, or equivalent.
Edinburgh, United kingdom
Hybrid
09-03-2026