A multinational defence organisation runs its security monitoring on a large, distributed Splunk estate, and is looking for the engineer who will own it. This is the senior technical voice on log collection and detection tooling for a cyber security data team, not a ticket-queue role.
What you would be doing
- Acting as the subject matter expert for the monitoring platform and everything that feeds it — advising other teams, sizing changes and taking the technical lead on related projects.
- Designing, deploying and maintaining distributed architectures, and keeping the whole estate installed, configured and behaving.
- Watching every component, spotting abnormal behaviour early in system, security and application logs, and taking the technical and the non-technical action needed to clear it.
- Keeping the service inside the performance targets agreed with the customers it protects.
- Integrating external tooling, and proposing the improvements that keep the environment current instead of merely alive.
- Writing up the business case and the implementation plan for change boards, then delivering the approved change with the other teams involved.
- Producing documentation, procedures and design notes, plus technical and executive reporting and the occasional briefing to a senior audience.
- Taking a turn on call, so that monitoring stays available when something breaks out of hours.
What you would bring
- Hands-on time administering Splunk in a large enterprise — deployment, installation, configuration and maintenance — and real experience of distributed designs.
- Expert-level background in log collection and security monitoring management, with the analytical habit of reading logs to diagnose rather than to confirm.
- Strong Linux administration and troubleshooting, and comfort with regular expressions.
- Scripting to take the repetition out of the work: Bash, Python or Ansible.
- A solid grounding in computer and communication security, networking, and where modern operating systems and applications tend to be weak.
- Clear technical writing and the ability to explain a complicated problem to people who do not share your background.
- Nice to have: Enterprise Security, SOAR and UBA, custom parsers, Git, cloud log collection, and an industry certification such as CISSP, CISM or a GIAC.
Extensions are offered where the work goes well. Applications are reviewed as they arrive.