workinengineering
BrowseField notes
workinengineering

Curated engineering jobs in Europe. Built to support the career path of engineering people at European companies across the EU, UK and EMEA.

Jobs

  • Browse all jobs
  • Remote jobs
  • Jobs in Germany
  • Jobs in Netherlands
  • Jobs in the UK
  • Field notes

About us

  • About
  • Contact
  • Privacy
  • Terms
  • Cookies

© 2026 workinengineering.eu — Made in Europe.

  • Email
workinengineering
BrowseField notes
  1. All roles
  2. BT Group PLC
  3. SIEM Security Engineer
BT Group PLC logo
BT Group PLC

SIEM Security Engineer

NewHybridMidBirmingham, the United KingdomSecurity
Apply directly at BT Group PLC

Our Take

SIEM Security Engineer at BT Group PLC based in Birmingham, focusing on developing and maintaining strategic SIEM solutions.

What you’ll do

  • Support the development, implementation, operation and support of BTs Strategic SIEM development
  • Design, develop, and maintain the ingestion of our security information and event management (SIEM) system
  • Leveraging Elasticsearch and related technologies to enhance threat detection, incident response, and overall security posture
  • Collaborate with Security analysts and application teams to provide clear design for the security scope of data ingestion
  • Support the configuration of Elasticsearch pipelines for data ingestion from various sources, primarily from Kafka
  • Enhance data enrichment by integrating threat intelligence feeds and contextual information
  • Design and implement SIEM solutions using Elasticsearch
  • Optimize SIEM rules, alerts, and dashboards for efficient threat detection

What they’re looking for

  • Proven experience in SIEM Detection Engineering
  • Experience using cyber security technologies such as NGFW, Proxies, IAM solutions
  • Experience of tuning security detection use cases
  • Experience with log source onboarding and normalisation
  • Strong analytical and troubleshooting skills with the ability to investigate complex security events
  • Understanding of MITRE ATT&CK and modern cyber threat techniques
  • Experience working with Security Operations and engineering stakeholders
  • Bachelor’s/Master’s degree in Computer Science, Information Systems, Engineering, or other related fields

What you get

  • 10% on target annual bonus
  • Access to an online private GP 24/7 for you and your immediate family
  • Market-leading paid carers leave with up to 2 weeks off
  • Equalised maternity, paternity, and adoption leave – 18 weeks’ full pay and 8 weeks’ half pay
  • Discounted EE and BT products, including mobile and broadband
  • Market leading Pension scheme – 5% from you and 10% from us
  • Holiday purchase scheme
  • Ability to select additional benefits including healthcare, dental, gym memberships

Skills & Focus Areas

  • SIEM
  • Elasticsearch
  • Kafka
  • Threat Intelligence
  • NGFW
  • Proxies
  • IAM

As posted by BT Group PLC

Job Req ID: 60935

Posting Date: 30th July 2026

Closing Date: 13th Aug 2026

Location: Birmingham

 

About the role

The new Network SIEM is essential to BT’s network security, meeting TSA requirements and improving our CAF level. Your role as a SIEM Application Engineer in Security Engineering is to support the development, implementation, operation and support of BTs Strategic SIEM development.  

We are seeking a skilled SIEM Security Engineer with expertise in SIEM and Security logging and monitoring to join our dynamic team. As a SIEM engineer, you will play a critical role in designing, developing, and maintaining the ingestion of our security information and event management (SIEM) system. Your focus will be on leveraging Elasticsearch and related technologies to enhance threat detection, incident response, and overall security posture. 

 

The role is hybrid (3 days in office) & based in Birmingham

What you’ll be doing

Data Ingestion and Enrichment: 

  • Collaborate with Security analysts and application teams to provide clear design for the security scope of data ingestion. 
  • Support the configuration of Elasticsearch pipelines for data ingestion from various sources, primarily from Kafka 
  • Enhance data enrichment by integrating threat intelligence feeds and contextual information. 


SIEM Solution Development: 

  • Collaborate with security analysts and architects to design and implement SIEM solutions using Elasticsearch. 
  • Optimize SIEM rules, alerts, and dashboards for efficient threat detection. 
  • Query Optimization and Performance Tuning: 
  • Write efficient Elasticsearch queries to retrieve relevant security events. 
  • Monitor and manage the performance of the SIEM infrastructure. 


Security Engineering: 

  • Contribute to security engineering projects, transitions, and transformations. 
  • Work closely with security operations and associated security incident response systems 
  • Stay informed about emerging threats and security best practices. 

Essential Skills / Experience

  • Proven experience in SIEM Detection Engineering. 
  • Experience using cyber security technologies such as NGFW, Proxies, IAM solutions  
  • Experience of tuning security detection use cases. 
  • Experience with log source onboarding and normalisation 
  • Strong analytical and troubleshooting skills with the ability to investigate complex security events. 
  • Understanding of MITRE ATT&CK and modern cyber threat techniques. 
  • Experience working with Security Operations and engineering stakeholders. 
  • Excellent technical documentation and communication skills. 
  • Bachelor’s/Master’s degree in Computer Science, Information Systems, Engineering, or other related fields 
  • 5+ years of engineering experience in delivering cybersecurity solutions 
  • Experience in key cyber technologies such as SIEM technologies (Elastic preferred), vulnerability management, access management and other commonly used Enterprise security controls. Ideally from both a development and operational perspective 

Desirable Skills / Experience

  • SIEM implementation and usage Experience of Elastic Stack (ELK) 
  • Knowledge of Offensive testing frameworks 
  • Knowledge of Linux, Windows and Network Administration 
  • Knowledge and experience of cloud services (public or private), OpenStack and K8S 
  • Cyber security qualifications 
  • Knowledge of Telecoms Security Act (TSA) 
  • Knowledge of architectural concepts such as microservices, service mesh. 
  • Knowledge of Git and Devops practices 
  • Knowledge of Terraform/Ansible systems 
  • Strong knowledge of security policy/regulatory frameworks 

Our Package

Tailored benefits make a real difference. That’s why we offer a comprehensive range to support your growth, wellbeing, and everyday life. You can design the package to suit you and your lifestyle. Your core benefits include: 

  • 10% on target annual bonus 
  • Access to an online private GP 24/7 for you and your immediate family 
  • Market-leading paid carers leave with up to 2 weeks off 
  • Equalised maternity, paternity, and adoption leave – 18 weeks’ full pay and 8 weeks’ half pay 
  • Discounted EE and BT products, including mobile and broadband 
  • Market leading Pension scheme – 5% from you and 10% from us 
  • Holiday purchase scheme 

You can select additional benefits, including healthcare, dental, gym memberships and more when you’re ready.

BT Group is the UK’s leading communications group and the holding company behind some of the country’s most recognised brands – including BT, EE, Openreach and Plusnet. Our purpose is as simple as it is ambitious: we connect for good.  Our customers include consumers, small, medium and large businesses, public sector organisations and other communications providers. 

BT Group’s role is about setting direction, unlocking value and creating the conditions for our brands and businesses to thrive.

Having come through the most capital-intensive phase of our fibre investment, our focus now is on what comes next – simplifying how we operate, using technology and AI to work smarter, and organising ourselves to serve customers better and grow sustainably. Group teams shape strategy, policy, brand, capital allocation and transformation, helping the whole organisation perform at its best.

We have a singular culture that unites all our people: we are customer-first challengers, who are committed, clear and connected. These behaviours unite us as one team to deliver for our colleagues, our customers, our stakeholders and the country.   Joining BT Group means working at the heart of a business that matters to the UK, with the opportunity to shape decisions, influence outcomes and help set the future course of one of the country’s most important companies.

Apply directly at BT Group PLC
Location
Birmingham, the United Kingdom
Work mode
Hybrid
Track
IC (Individual Contributor)
Seniority
Mid
Type
FULL_TIME
PostedJul 31
BT Group PLC logo
BT Group PLC
bt.com
View all 20 BT Group PLC roles →

Was this listing helpful?