Rodeo
Get started

HCLTech

SIEM consultant

Manchester
Posted about 23 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

SIEM Consultant

Location: Remote, UK
Travel: If required can travel 1-2 days from office

Job Description

In-scope technologies/products: Splunk, Linux

Key responsibilities

  • Identify critical applications and telemetry sources for SIEM onboarding.
  • Optimise Microsoft Sentinel ingestion and cost drivers while preserving detection value.
  • Develop or tune threat analytics and detection use cases.
  • Plan automation, sandboxing and SOAR workflows with ServiceNow integration touchpoints.
  • Support breach attack simulation POC and triage process improvement.
  • Design, implement, and continuously improve security monitoring and threat detection capabilities across the organization.
  • Onboarding, configuration, and optimization of Microsoft Sentinel and other SIEM platforms.
  • Develop and maintain detection rules, use cases, alerts, dashboards, and security monitoring processes.
  • Build and enhance SOAR playbooks to automate repetitive security operations and incident response activities.
  • Perform threat hunting, incident investigations, and root cause analysis to identify and address security threats.
  • Integrate security tools, cloud platforms, endpoints, and network devices into the SIEM ecosystem.
  • Work closely with SOC analysts, security teams, and technology stakeholders to improve visibility, detection coverage, and response effectiveness.
  • Provide recommendations to strengthen the organization's overall security posture and monitoring maturity.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Required skills and experience

  • Microsoft Sentinel and SIEM onboarding
  • Detection engineering and analytics tuning
  • SOAR playbooks and automation
  • Threat simulation and sandboxing
  • SOC process and incident workflow integration
  • Experience in Security Operations, SIEM Engineering, Threat Detection, or Cyber Security Monitoring.
  • Strong hands-on experience with Microsoft Sentinel, including log onboarding, analytics rules, workbooks, hunting queries, and incident management.
  • Experience working with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, ArcSight, or similar solutions.
  • Good understanding of security operations, security monitoring, incident response, and threat hunting practices.
  • Experience developing and tuning detection use cases to reduce false positives and improve threat visibility.
  • Hands-on experience with SOAR platforms and security automation workflows.
  • Strong knowledge of log analysis, event correlation, and security investigations across cloud, endpoint, identity, and network environments.
  • Familiarity with the MITRE ATT&CK Framework, threat intelligence integration, and detection engineering concepts.
  • Experience with Microsoft security technologies such as Microsoft Defender XDR, Defender for Endpoint, Defender for Cloud, and Entra ID is highly desirable.
  • Strong analytical, troubleshooting, and stakeholder communication skills.
  • Experience supporting or leading SIEM/SOC transformation, optimization, or modernization initiatives is preferred.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Manchester, England, United Kingdom

Sign up to applySee more jobs like this