BT Group
SIEM Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Title: SIEM Security Engineer
Req ID: 62443
Job Function: Cyber Security
Posting Start Date: 03/09/2026
Posting End Date: 01/10/2026
Division: Networks
Job Location: GBR-Birmingham-Three Snowhill
Advertised Salary: Competitive with Great Benefits
Job Req ID: 62443
Posting Date: 3rd Sep 2026
Closing Date: 1st Oct 2026
Location: Birmingham
About The Role
The new Network SIEM is essential to BT’s network security, meeting TSA requirements and improving our CAF level. Your role as a SIEM Application Engineer in Security Engineering is to support the development, implementation, operation, and support of BT's Strategic SIEM development. We are seeking a skilled SIEM Security Engineer with expertise in SIEM and Security logging and monitoring to join our dynamic team. As a SIEM engineer, you will play a critical role in designing, developing, and maintaining the ingestion of our security information and event management (SIEM) system. Your focus will be on leveraging Elasticsearch and related technologies to enhance threat detection, incident response, and overall security posture.
The role is hybrid (3 days in office) & based in Birmingham
What You’ll Be Doing
Data Ingestion and Enrichment:
- Collaborate with Security analysts and application teams to provide clear design for the security scope of data ingestion.
- Support the configuration of Elasticsearch pipelines for data ingestion from various sources, primarily from Kafka
- Enhance data enrichment by integrating threat intelligence feeds and contextual information.
- Ingest data from various networking equipment, servers, firewalls, and security appliances across multiple vendors.
SIEM Solution Development:
- Collaborate with security analysts and architects to design and implement SIEM solutions using Elasticsearch.
- Continuously improving threat detection capabilities by tuning and optimizing existing use cases and retiring use cases no longer providing value.
Query Optimization and Performance Tuning:
- Designing, implementing, and managing security detection use cases across a range of technologies to ensure timely alerting of security events and incidents to Security Operations staff.
- Monitor and manage the performance of the SIEM infrastructure.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Security Engineering:
- Contribute to security engineering projects, transitions, and transformations.
- Work closely with security operations and associated security incident response systems
- Stay informed about emerging threats and security best practices.
Essential Skills / Experience
- Proven experience in SIEM Detection Engineering.
- Experience using cyber security technologies such as NGFW, SIEM, Proxies, IAM solutions
- Experience of tuning security detection use cases. Experience with log source onboarding and normalization
- Strong analytical and troubleshooting skills with the ability to investigate complex security events.
- Understanding of MITRE ATT&CK and modern cyber threat techniques.
- Experience working with Security Operations and engineering stakeholders.
- Excellent technical documentation and communication skills.
- Bachelor’s/Master’s degree in Computer Science, Information Systems, Engineering, or other related fields 5+ years of engineering experience in delivering cybersecurity solutions
- Experience in key cyber technologies such as SIEM technologies (Elastic preferred), vulnerability management, access management, and other commonly used Enterprise security controls. Ideally from both a development and operational perspective
Desirable Skills / Experience
- SIEM implementation and usage
- Experience of Elastic Stack (ELK)
- Knowledge of Offensive testing frameworks
- Knowledge of Linux, Windows, and Network Administration
- Knowledge and experience of cloud services (public or private), OpenStack, and K8S
- Cyber security qualifications
- Knowledge of Git and DevOps practices
- Knowledge of Terraform/Ansible systems
- Strong knowledge of security policy/regulatory frameworks including Telecoms Security Act (TSA)
Our Package
Tailored benefits make a real difference. That’s why we offer a comprehensive range to support your growth, wellbeing, and everyday life. You can design the package to suit you and your lifestyle. Your core benefits include:


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- 10% on target annual bonus
- Access to an online private GP 24/7 for you and your immediate family
- Market-leading paid carers leave with up to 2 weeks off
- Equalised maternity, paternity, and adoption leave – 18 weeks’ full pay and 8 weeks’ half pay
- Discounted EE and BT products, including mobile and broadband
- Market leading Pension scheme – 5% from you and 10% from us
- Holiday purchase scheme
You can select additional benefits, including healthcare, dental, gym memberships, and more when you’re ready.
BT Group
BT Group is the UK’s leading communications group and the holding company behind some of the country’s most recognized brands – including BT, EE, Openreach, and Plusnet. Our purpose is as simple as it is ambitious: we connect for good. Our customers include consumers, small, medium, and large businesses, public sector organizations, and other communications providers.
BT Group’s role is about setting direction, unlocking value, and creating the conditions for our brands and businesses to thrive.
Having come through the most capital-intensive phase of our fibre investment, our focus now is on what comes next – simplifying how we operate, using technology and AI to work smarter, and organizing ourselves to serve customers better and grow sustainably. Group teams shape strategy, policy, brand, capital allocation, and transformation, helping the whole organization perform at its best.
We have a singular culture that unites all our people: we are customer-first challengers, who are committed, clear, and connected. These behaviors unite us as one team to deliver for our colleagues, our customers, our stakeholders, and the country. Joining BT Group means working at the heart of a business that matters to the UK, with the opportunity to shape decisions, influence outcomes, and help set the future course of one of the country’s most important companies.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills