SIEM Engineer – Reading
职位介绍
A SIEM Engineer in Reading is responsible for leading the onboarding and integration of log sources into Microsoft Sentinel, ensuring comprehensive security telemetry. They develop custom parsers and data transformations to enhance ingested data, optimise KQL queries, and create analytic rules aligned with emerging threats. The role involves designing and maintaining detection logic, automating responses using Logic Apps and SOAR workflows, and implementing CI/CD pipelines with Azure DevOps or Git for controlled deployment. Continuous tuning of detections is required to improve accuracy and reduce false positives, with an emphasis on automation and efficiency in security operations. The position expects technical skills in security information and event management, cloud platforms, scripting, and automation tools, along with a proactive approach to threat detection and response.
查看完整职位
工作职责、任职要求、技能与福利 — 免费创建账号即可查看。
或
已有账户?
登录您可能也感兴趣的职位
暂无高度相似的职位 — 以下是最新职位。