Skip to content

Splunk SIEM Engineer

HelloKindredKnutsford, ENG, UKJuly 25, 2026
Hybrid
Full-time
SOC
Mid

Company Description

Who is HelloKindred?

HelloKindred are specialists in staffing marketing, creative and technology roles, offering a range of talent solutions that can be delivered on-site, remotely or hybrid.

Our vision is to make work accessible and people’s lives better. We do this by disrupting traditional employment barriers – connecting ambitious talent to flexible opportunities with trusted brands.

Job Description

Anticipated Contract End Date: November 30, 2026
Work set up: Hybrid (3 days per week in office)
Clearance required: BPSS (Contractor must be eligible)

Our client in the Information Technology and Services industry is looking for a Splunk SIEM Engineer to design, develop, and enhance security software solutions that provide business, platform, and technology capabilities for customers and colleagues. This role focuses on administering and optimizing Splunk Enterprise Security, Microsoft Sentinel, and supporting modern Security Operations by developing SIEM use cases, managing data pipelines, automating security workflows, and strengthening enterprise cyber defense capabilities.

What you will do:

  • Design, develop, and improve SIEM solutions that support enterprise security operations.
  • Administer, manage, and maintain Splunk Enterprise and Splunk Enterprise Security environments.
  • Develop SIEM use cases, correlation searches, and detection rules.
  • Build and maintain Splunk data models to support advanced analytics and security monitoring.
  • Configure and support Splunk Cloud environments.
  • Administer and maintain Microsoft Sentinel security monitoring capabilities.
  • Manage log ingestion, routing, parsing, normalization, and transformation using Splunk Enterprise and Cribl Stream.
  • Develop automation workflows and security playbooks using SOAR technologies.
  • Analyze security events and support threat detection and incident response activities.
  • Troubleshoot security monitoring, network, and infrastructure issues.
  • Create technical documentation, operational procedures, and runbooks.
  • Develop automation scripts and integrations using Python, PowerShell, SPL, KQL, and SQL.
  • Support CI/CD pipelines using tools such as GitLab and Jenkins.
  • Collaborate with security, infrastructure, and engineering teams to improve monitoring capabilities.
  • Support cloud security monitoring across AWS and Azure environments.
  • Ensure security monitoring solutions align with governance, compliance, and regulatory requirements.

Qualifications

  • Bachelor's degree or equivalent professional experience.
  • Proven experience administering and developing Splunk Enterprise environments.
  • Strong expertise with Splunk Enterprise Security (SIEM), including administration, management, maintenance, and correlation search development.
  • Experience designing and managing Splunk data models.
  • Hands-on experience with Splunk Cloud.
  • Experience administering Microsoft Sentinel.
  • Strong understanding of SIEM architecture, data models, correlation rules, and administrative functions.
  • Experience working in large enterprise Security Operations environments supporting 10,000+ endpoints.
  • Hands-on experience managing log ingestion, routing, parsing, normalization, and transformation using Cribl Stream or similar technologies.
  • Experience developing SOAR playbooks and automated incident response workflows.
  • Solid understanding of network architecture, firewalls, proxies, common attack vectors, and security troubleshooting.
  • Strong technical communication and documentation skills, including the creation of runbooks and operational procedures.
  • Proficiency with Python, PowerShell, KQL, SPL, and SQL for automation and analytics.
  • Experience with CI/CD tools such as GitLab, Jenkins, or similar platforms.
  • Knowledge of AWS and Azure cloud security concepts and modern infrastructure.
  • Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms is preferred.
  • Familiarity with Infrastructure as Code tools such as Chef and Ansible is desirable.
  • Knowledge of compliance frameworks including SOX, PCI-DSS, and GDPR is advantageous.
  • Professional security certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja are highly desirable.
  • Eligibility to obtain BPSS clearance is required.

Additional Information

Please submit a CV/resume (mandatory) along with your application.

All your information will be kept confidential according to EEO guidelines.

Candidates must be legally authorized to live and work in the country where the position is based, without requiring employer sponsorship.

HelloKindred is committed to fair, transparent, and inclusive hiring practices. We assess candidates based on skills, experience, and role-related requirements.

We appreciate your interest in this opportunity. While we review every application carefully, only candidates selected for an interview will be contacted.

HelloKindred is an equal opportunity employer. We welcome applicants of all backgrounds and do not discriminate on the basis of race, colour, religion, sex, gender identity or expression, sexual orientation, age, national origin, disability, veteran status, or any other protected characteristic under applicable law.

Job Details

Experience

Mid

Tools & Tech

Ansible
AWS
Azure
Chef
GitLab
Jenkins
Microsoft Sentinel
PowerShell
Python
Splunk
SQL

Preferred Certs

CISSP
GCIH