Security Automation & Detection Engineer

placeCambridge calendar_month 

A multinational semiconductor and software design company is seeking a Security Automation & Detection Engineer for a 6-month contract to start ASAP, based in Cambridge (Hybrid), Inside IR35.

Role Overview:
Utilising knowledge of security operations, incident response, and detection engineering, you will be responsible for the delivery of SIEM detections and security automations.

The successful candidate will be proficient in automation and orchestration tools (e.g., SOAR platforms, scripting languages like Python, PowerShell) and have experience with integrating security tools (e.g., SIEM, EDR, firewalls) APIs, and Case Management tools for data enrichment.

Responsibilities:
Build security automations, logging, and SIEM detections to improve the Cyber Defence Operation’s efficiency, scalability, and incident response capabilities.
Design, implement, and maintain automated workflows and playbooks to streamline CDO operations, including incident response, threat hunting, cyber threat intelligence and vulnerability management.
Collaborate with Cyber Defence Operation analysts to identify repetitive tasks and automate them to improve operational efficiency.
Collaborate with Threat Intelligence, Incident Response, and Attack Surface Management to build and tune robust SIEM detections for both proactive and reactive response actions.
Continuously evaluate automation solutions for performance, reliability, and scalability, making improvements, as necessary.
Collaborate with third-party vendors and service providers to leverage automation opportunities and ensure successful integrations.

Lead technical migration of log sources into Microsoft Sentinel SIEM.

Required Skills and Experience:
Demonstrated ability in cybersecurity, with at least 3 years in a technical role in security operations and/or security software development.
Solid understanding of security operations, automation standard processes, detection engineering and SIEM management.
Experience with cloud security tools and platforms (e.g. Azure, AWS Google Cloud) and their integration into SOC operations.
Vendor-specific certifications for Security orchestration, automation, and response (SOAR) platforms (e.g., Sentinel SOAR, Splunk SOAR, Palo Alto Cortex XSOAR).

Experience contributing to large-scale, sprint-based, security automation and detection engineering projects.

Desirable Skills and Experience: Ability to develop and implement long-term automation strategies aligned with security operation objectives.

Ability to translate technical concepts into clear, actionable insights for technical and non-technical partners.
Meticulous focus on ensuring accuracy, reliability, and security in automation workflows

Consistent record of implementing automation and integration solutions in a SOC or similar environment

#4661481 - Karl Randall

apartmentMichael PageplaceStevenage, 26 mi from Cambridge
to expand their CRM team in Hertfordshire. Job Description  •  Implement and manage CRM strategies to enhance customer engagement and increase revenue.  •  You will have a focus on the more technical aspects e.g. triggers/automation.  •  Regularly review...
local_fire_departmentUrgent

Automation Engineering Manager

apartmentTescoplaceWelwyn Garden City, 32 mi from Cambridge
technology is key to the future of Tesco, making sure automation is at the heart of our decisions.  •  Benchmark across the industry to include best practices and drive continuous improvement.  •  Establishing and maintaining system development standards...
check_circleNew offer

Basildon - Automation Engineer

placeBasildon, 42 mi from Cambridge
including the pharmaceutical industry. They are now able to appoint an Automation Engineer to join their team. As an Automation Engineer, you will work alongside the electricians and panel builders to assist in the design and build of the control systems...