Cyber Security Specialist – SIEM Engineering
4 days ago
Cyber Security Specialist – SIEM Engineering
LocationAsda House
Employment TypeFull time
Contract TypePermanent
Hours Per Week37.5
SalaryCompetitive salary plus benefits
CategoryCyber Security
Closing Date7 November 2025
Location: Leeds (Asda House) / Hybrid (3 days in office)
Department: Technology – Cyber Security
Reports to: SOC and Incident Response Manager
Role PurposeWe are looking for a Cyber Security Specialist – SIEM Engineer to strengthen Asda's detection and response capabilities. This is a hands-on engineering role, acting as a key enabler for the SOC and Incident Response Team (IRT), ensuring Asda gets maximum value from its investment in Microsoft Sentinel and the wider Defender XDR suite. The role will be responsible for onboarding and tuning log sources, building and optimising detections, and driving continuous improvement in SOC maturity.
Key Responsibilities- Engineer, configure, and maintain Microsoft Sentinel as Asda's SIEM, ensuring effective log ingestion, correlation, and alerting alongside existing Security Engineering function.
- Build, tune, and optimise detections, analytic rules, and automation (SOAR) to support SOC monitoring and IRT investigations.
- Integrate and enhance visibility across the Microsoft Defender XDR ecosystem, driving log source value and efficiency (Defender for Endpoint, Identity, Office 365, Cloud Apps, Entra ID).
- Onboard and manage diverse log sources (cloud, endpoint, network, SaaS, third party) to enrich SOC coverage.
- Support SOC analysts and incident responders with deep technical investigations and context enrichment.
- Develop dashboards, workbooks, and metrics to demonstrate SOC effectiveness and identify gaps.
- Partner with Threat Intelligence to translate IOCs/TTPs into actionable detections mapped to MITRE ATT&CK.
- Lead continuous improvement efforts to mature SIEM and SOC capabilities, reducing false positives and increasing detection fidelity.
- Maintain awareness of Microsoft's evolving security capabilities; recommend and implement enhancements to strengthen resilience.
- Document engineering standards, playbooks, and knowledge articles for ongoing SOC/IRT operations.
- Strong hands-on experience with Microsoft Sentinel SIEM — log source integration, KQL queries, analytic rule development, automation.
- Familiarity with the Microsoft Defender XDR suite (Defender for Endpoint, Identity, O365, Cloud Apps).
- Understanding of SOC operations, incident response workflows, and detection engineering principles.
- Proficiency in Kusto Query Language (KQL) for writing detections and reports.
- Knowledge of logging, telemetry, and security data sources across cloud and on-premise environments.
- Experience building and maintaining SOAR playbooks (preferably Microsoft Logic Apps).
- Strong problem-solving and analytical skills; ability to identify gaps and implement solutions.
- Effective communicator; able to translate technical details into value for SOC and business stakeholders.
Desirable:
- Microsoft certifications (e.g., SC-200, SC-300, AZ-500, MS-500).
- Familiarity with automation and scripting (PowerShell, Python).
- Experience with threat hunting, purple teaming, or threat-informed defence.
- Exposure to large-scale retail or enterprise environments.
- Sentinel SIEM is well-engineered, integrated, and delivering high-fidelity detections to SOC.
- SOC analysts and IRT can respond faster and with greater confidence thanks to improved visibility and automation.
- False positives are reduced; alerting is tuned and aligned to real-world threats.
- Coverage across Asda's critical systems (cloud, endpoint, identity, email, SaaS) is comprehensive and monitored.
- Continuous improvement is evident — SOC maturity increases quarter by quarter.
- Being a key engineer enabling Asda's frontline cyber defence.
- Hands-on experience with Microsoft's leading-edge security stack at enterprise scale.
- Opportunity to influence SOC/IRT strategy and tooling improvements.
- A collaborative, values-led culture with career growth opportunities.
- Hybrid working, competitive benefits, and the chance to protect a brand trusted by millions.
- One team: collaboration across SOC, IRT, Threat Intel, Risk, and wider Technology.
- Customer-first: protecting trust is central to everything we do.
- Innovative: continuously improving detections, automation, and resilience.
- Ethical: acting transparently and responsibly in all we deliver.
Everything you'll love
To ensure we balance moments where we know we need to collaborate together and the need for flexibility, Asda has a hybrid way of working with a minimum 3 days a week in one of our Home Offices. Over and above this, each area of Asda may have additional requirements which may require spending more days in the office, visiting suppliers, stores or depots.
You will also get an excellent benefits package including:
- Discretionary company bonus
- Company pension up to 7% matched
- Company Car allowance of £5,700
- 15% colleague discount in store and online
- Free access to wellbeing services such as Wagestream, 24/7 virtual GP, counselling, health and dental cash plans and a 24/7 employee assistance helpline, alongside discounts across a range of services and activities, from airport parking, enhanced to theme parks and cinemas.
- Asda Allies Inclusion Networks – helping colleagues to make sure everybody is included and that our differences are recognised and celebrated
- Excellent parental leave policies, including maternity & adoption leave, paternity leave, shared parental leave, neonatal care leave, and support for those doing fertility treatments.
We want all colleagues to be able to bring their best and true selves to work, every day. Simply put, we want our colleagues to be Proud to be Asda and proud to be themselves"
-
Cyber Security Specialist – SIEM Engineering
6 days ago
Leeds, Leeds, United Kingdom Asda Full timeJob TitleCyber Security Specialist – SIEM EngineeringLocationAsda HouseEmployment TypeFull timeContract TypePermanentHours Per Week37.5SalaryCompetitive salary plus benefitsCategoryCyber SecurityClosing Date7 November 2025Location: Leeds (Asda House) / Hybrid (3 days in office)Department: Technology – Cyber SecurityReports to: SOC and Incident Response...
-
Cyber Security Analyst
2 weeks ago
Leeds LS TE, United Kingdom SEP2 Full time £24,000 - £40,000 per yearOVERVIEWWorking for one of the UKs fastest-growing specialists in Cyber Security products and services, the successful candidates will work within the Security Operations Centre (SOC) and will be responsible for supporting leading security solutions and services for our clients.The successful candidates will need to not only be technically minded but also be...
-
Cyber Security Lead
4 days ago
Leeds, United Kingdom ITECCO Full time**Lead Security Engineer - £70k+ - Leeds** My client, being a specialist in app protection and business critical systems, are looking for a dynamic, experienced cyber security professional who will play a key role in delivering my clients cyber security services, with a particular focus on improvingand growing their service offering. **? Benefits**: - 33...
-
Principal Cyber Security Engineer
6 days ago
Leeds, United Kingdom Catorfaen Full timeIn 2022 we built out an exciting SIEM/SOAR and ManagedDetection and Response service called SEP2.security, built upon Google CloudSecurity’s Chronicle stack. Due to customer demand, we are now looking to hire aPrincipal Cyber Security Engineer to join this every growing team. The Security Intelligence Services team, that this role issituated in, provides...
-
Junior Cyber Security Analyst
2 hours ago
Leeds, United Kingdom Oscar Technology Full time**Job title**: Junior Cyber Security Analyst **Salary**: up to £23k + shares options, DOE **Location**: Leeds - 4 times a week in the office **Benefits**: Pension scheme + Vitality Health private health insurance **Start**: ASAP We are looking for a **Junior Cyber Security Analyst** for a respected cybersecurity consultancy established over ten years ago,...
-
Information Security Consultant £60k
1 week ago
Leeds, United Kingdom Pearson Carter Full timePearson Carter are currently working with a Global Consultancy who are in search of a Strong Infrastructure Specialist with Deep Microsoft Tech knowledge in security to join their growing team! My client has had a big IT investment and because of this they’re looking to get started on some exciting new projects. The company has projects with Microsoft...
-
Senior Cyber Security Analyst
2 weeks ago
Leeds LS AP, United Kingdom NHS Full timeThe Senior Security Analyst (Ops) sits within the Protective Monitoring function of the Cyber Security Operations Centre (CSOC). The CSOC is made up of Protective Monitoring, Incident Management, Threat Operations, Engineering and Consultancy. The role is a Tier 3 analyst in the Cloud Protective Monitoring Sub team.Cyber Operations purpose is to support safe...
-
Cyber Security Lead
2 weeks ago
Leeds, United Kingdom ITECCO Full time**Cyber Security Team Lead - £70k+ - Leeds** I am looking for a dynamic, experienced cyber security professional who will play a key role in delivering my clients cyber security services, with a particular focus on improving and growing their service offering. **Benefits**: - 25 days holiday plus bank holidays - Vitality Health - Share options - Hybrid...
-
Security Operations Analyst: SIEM, EDR
1 week ago
Leeds, United Kingdom tendersglobal Full timeA forward-thinking organization in Leeds is seeking a Security Operations Analyst to join their InfoSec team. This role offers a fantastic chance to gain hands-on experience in cybersecurity while playing a pivotal role in protecting systems and data against cyber threats. Salary up to £40,000 with additional bonuses and a strong pension plan. Perspective...
-
Cyber Security Trainee
4 days ago
Leeds, United Kingdom NHS England Full timeAbout the role Cyber Operations purpose is to support safe care and build public trust by building NHS England’s cyber resilience and enabling the wider health system to be cyber resilient, supporting Transformation Directorate’s purpose of delivering the best care and outcomes for the NHS. The Cyber Operations sub-directorate consists of 4 operational...