Job Description :
We are looking for an experienced Security Engineer to join our Information Security function, operating as a core contributor within the Security Operations Centre (SOC) and cloud security engineering practice. This is a technically deep, hands-on role centred on Palo Alto Cortex XSIAM/XSOAR as our primary SIEM and SOAR platform, alongside CrowdStrike Falcon endpoint protection, multi-cloud logging ingestion, and identity integration across our Microsoft estate.
The successful candidate will design, build and maintain the integrations that feed security telemetry into our detection and response capabilityspanning AWS, GCP and Azurewhile working collaboratively with IT to ensure the health and integrity of our Entra ID and Microsoft 365 connectors.
You will operate within an environment that places equal weight on engineering rigour and security assurance, contributing to playbook development, alert tuning and the continuous improvement of our detection posture.
Key Responsibilities :
SIEM & SOAR Engineering (Palo Alto Cortex) :
- Design, deploy and maintain log source integrations into Palo Alto Cortex XSIAM / XSOAR, ensuring normalisation, parsing accuracy and data quality across all connected sources.
- Develop, test and continuously improve SOAR playbooks for automated triage, enrichment and response across key incident types.
- Own SIEM content including detection rules, correlation policies, dashboards and alert thresholds; perform ongoing tuning to reduce false-positive volumes.
- Maintain platform health including connector status monitoring, API rate-limit management and capacity planning for log ingestion pipelines.
- Produce and maintain engineering documentation including integration runbooks, playbook specifications and change records in accordance with CAB policy.
Endpoint Security Engineering (CrowdStrike Falcon) :
- Administer and engineer the CrowdStrike Falcon platform, including sensor deployment management, policy configuration and response workflow alignment with SOC procedures.
- Configure and maintain Falcon data connectors into the SIEM, ensuring EDR telemetry is enriched and actionable within the detection pipeline.
- Contribute to host-based detection content and work with the SOC team to validate alert fidelity from Falcon-sourced events.
- Support incident response activities requiring Falcon RTR (Real Time Response) capabilities where required.
Cloud Security Logging & Integration :
- Engineer and maintain security log collection from multi-cloud environments into the SIEM, including :
1. AWS configure and operate GuardDuty, Security Hub, CloudTrail, VPC Flow Logs and S3 access logging; manage event forwarding via EventBridge and SQS/SNS pipelines.
2. Azure configure and maintain Microsoft Defender for Cloud, Azure Monitor Diagnostic Settings and Entra ID audit and sign-in log ingestion.
3. GCP configure and maintain Cloud Audit Logs, Security Command Centre findings export and Pub/Sub-based log forwarding into the SIEM.
- Ensure cloud logging coverage aligns with the organisations detection requirements and regulatory obligations, and identify and remediate gaps in telemetry coverage.
- Maintain cloud-side IAM roles and service principals used for log collection with least-privilege principles.
Microsoft Entra ID & Office 365 Integration :
- Work alongside the IT team to maintain and improve security-relevant integrations between Entra ID and the SIEM, including Conditional Access policy audit logging, risky sign-in alerting and identity-based detection use cases.
- Support the health and configuration of Microsoft 365 Defender connectors, including Exchange Online, SharePoint and Teams audit log ingestion.
- Assist in periodic reviews of Entra ID security configuration posture, including MFA policy coverage, guest account hygiene and privileged role assignments from a security monitoring perspective.
- Act as a technical liaison between Information Security and IT on identity-related security matters, escalating findings through appropriate governance channels.
SOC Operations & Continuous Improvement :
- Contribute to the SOC as a Tier 2/3 resource on complex investigations, providing engineering context to support analyst triage.
- Participate in threat-led detection engineering, translating threat intelligence and MITRE ATT&CK TTPs into actionable detection logic.
- Support vulnerability and configuration management activities where they relate to SIEM-connected assets.
- Contribute to weekly and monthly SOC reporting by maintaining the accuracy and completeness of underlying data sources and metrics.