HCLTech
SIEM consultant

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
SIEM Consultant
Location: Remote, UK
Travel: If required can travel 1-2 days from office
Job Description
In-scope technologies/products: Splunk, Linux
Key responsibilities
- Identify critical applications and telemetry sources for SIEM onboarding.
- Optimise Microsoft Sentinel ingestion and cost drivers while preserving detection value.
- Develop or tune threat analytics and detection use cases.
- Plan automation, sandboxing and SOAR workflows with ServiceNow integration touchpoints.
- Support breach attack simulation POC and triage process improvement.
- Design, implement, and continuously improve security monitoring and threat detection capabilities across the organization.
- Onboarding, configuration, and optimization of Microsoft Sentinel and other SIEM platforms.
- Develop and maintain detection rules, use cases, alerts, dashboards, and security monitoring processes.
- Build and enhance SOAR playbooks to automate repetitive security operations and incident response activities.
- Perform threat hunting, incident investigations, and root cause analysis to identify and address security threats.
- Integrate security tools, cloud platforms, endpoints, and network devices into the SIEM ecosystem.
- Work closely with SOC analysts, security teams, and technology stakeholders to improve visibility, detection coverage, and response effectiveness.
- Provide recommendations to strengthen the organization's overall security posture and monitoring maturity.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Required skills and experience
- Microsoft Sentinel and SIEM onboarding
- Detection engineering and analytics tuning
- SOAR playbooks and automation
- Threat simulation and sandboxing
- SOC process and incident workflow integration
- Experience in Security Operations, SIEM Engineering, Threat Detection, or Cyber Security Monitoring.
- Strong hands-on experience with Microsoft Sentinel, including log onboarding, analytics rules, workbooks, hunting queries, and incident management.
- Experience working with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, ArcSight, or similar solutions.
- Good understanding of security operations, security monitoring, incident response, and threat hunting practices.
- Experience developing and tuning detection use cases to reduce false positives and improve threat visibility.
- Hands-on experience with SOAR platforms and security automation workflows.
- Strong knowledge of log analysis, event correlation, and security investigations across cloud, endpoint, identity, and network environments.
- Familiarity with the MITRE ATT&CK Framework, threat intelligence integration, and detection engineering concepts.
- Experience with Microsoft security technologies such as Microsoft Defender XDR, Defender for Endpoint, Defender for Cloud, and Entra ID is highly desirable.
- Strong analytical, troubleshooting, and stakeholder communication skills.
- Experience supporting or leading SIEM/SOC transformation, optimization, or modernization initiatives is preferred.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London