SIEM Engineer

Hybrid

About this role

What you'll be doing:

As a SIEM Engineer at Atech, you will play a key role in designing, implementing, and optimising security monitoring solutions across a diverse range of customer environments. Working primarily with Microsoft Sentinel, Microsoft Defender, and the wider Microsoft Security ecosystem, you will help onboard customers into our Managed SOC service while supporting them in strengthening and maturing their overall security posture.

 

This role combines technical engineering, detection development, automation, and customer engagement. You will be responsible for building and maintaining high-quality detections, configuring data integrations, tuning alerting, and developing automations that improve both the effectiveness and efficiency of our Security Operations Centre (SOC). You will work closely with SOC Analysts, Security Consultants, Engineers, and customers to deliver innovative security solutions that help organisations identify, investigate, and respond to threats more effectively.

 

As part of a growing security practice, you will have the opportunity to shape the future of Atech's security services by contributing to detection engineering, automation initiatives, internal tooling, and service improvements. This is an excellent opportunity for someone who is passionate about cyber security, enjoys solving complex technical challenges, and wants to work with cutting-edge Microsoft security technologies.

 

Key Responsibilities

  • Design, implement, and maintain detections, analytics rules, workbooks, watchlists, and automations within Microsoft Sentinel.
  • Onboard new customers into Atech's Managed SOC service, including configuring integrations, data connectors, and monitoring capabilities.
  • Optimise and tune alerts to improve detection quality, reduce false positives, and enhance analyst efficiency.
  • Develop and maintain security monitoring content aligned to customer requirements and emerging threats.
  • Design and implement automation solutions using Microsoft Sentinel, Logic Apps, PowerShell, Python, and other supporting technologies.
  • Identify opportunities to improve and streamline security operations through automation and process improvement.
  • Support incident detection and response activities through the development of tooling, workflows, and detection capabilities.
  • Develop and maintain internal security tooling, scripts, and deployment pipelines.
  • Work collaboratively with SOC Analysts and Engineers to continuously improve security monitoring and operational effectiveness.
  • Contribute to technical designs, peer reviews, and security-focused projects across the wider business.
  • Create and maintain clear technical documentation, standards, processes, and procedures.
  • Produce technical reports, dashboards, and service summaries for customers and internal stakeholders.
  • Assist customers and colleagues in understanding and adopting Microsoft security technologies and best practices.
  • Stay current with emerging cyber threats, attack techniques, and advancements within the Microsoft Security ecosystem.
  • Participate in training, certifications, and continuous professional development to support your career growth and ensure Atech remains at the forefront of security detection and response.

We want to hear from you if you:

  • Are UK-based with full right to work in the UK.
  • Have hands-on experience with Microsoft Sentinel, Microsoft Defender, or similar SIEM/SOC technologies.
  • Are passionate about cyber security and keeping up with emerging threats and attack techniques.
  • Have experience with KQL, PowerShell, Python, or other scripting and automation tools.
  • Enjoy solving complex technical challenges and improving processes through automation.
  • Can communicate confidently with both technical and non-technical audiences.
  • Thrive in collaborative environments and enjoy working with customers and colleagues.
  • Have an interest in detection engineering, threat hunting, security monitoring, and incident response.
  • Take ownership of your work, manage priorities effectively, and adapt in a fast-paced environment.
  • Are committed to continuous learning, professional development, and knowledge sharing.
  • Have experience using AI tools such as Microsoft Copilot to enhance productivity and streamline workflows.
  • Hold Microsoft security certifications such as SC-200, AZ-500, or SC-300.

Bonus Points If You:

  • Have experience with Azure Logic Apps, Azure Functions, Terraform, Bicep, or Infrastructure as Code (IaC).
  • Have worked within a SOC, MSSP, or Managed Security Services environment.
  • Have experience with Detection-as-Code or Content-as-Code practices.
  • Have exposure to threat intelligence, threat hunting, malware analysis, or purple team activities.
  • Have integrated third-party security products and data sources into Microsoft Sentinel.
  • Have implemented AI capabilities, such as Copilot, within automations, workflows, or internal tooling.
  • Contribute to security tooling, open-source projects, technical content, or security research.

What's in it for me?

  • Competitive salary and benefits package.
  • Flexible hybrid or remote working model 
  • Exposure to a broad range of cyber security technologies and customer environments.
  • Opportunity to work on complex and high-impact security incidents.
  • Ongoing learning, certification and professional development support.
  • Clear career progression within a growing cyber security practice.
  • A collaborative and supportive team environment where knowledge sharing is encouraged.
  • The opportunity to influence SOC maturity, service innovation and security outcomes for our customers.

Who you'll be doing it for:

Atech part of the Iomart Group is a highly accredited Microsoft Partner who delivers transformed technology with managed services. Our team of certified Microsoft experts align with your team to deliver an excellent service tailored to your individual needs, 24/7/365.

 

Our services support 25,000 users globally and proactively monitor 45,000+ devices in key areas:

  • Azure infrastructure managed service
  • Modern Workplace: Office 365, Microsoft 365, and Azure Virtual Desktop
  • Managed Security and SOC with Microsoft Defender, Sentinel

What to do next:

Please click apply if you like the sound of this role. If you do not have an up to date CV or want to have a chat about the role first, please contact us on [email protected].

 

We’re an equal opportunities employer and want our vacancies to be available to all, so if you need us to make any reasonable adjustments during the process then just let us know.

Company at a glance

Iomart combines cutting-edge cloud technology with deep industry expertise to help organisations transform with confidence. From secure infrastructure and data protection to managed cloud services and modern work, we deliver tailored solutions that support resilience, agility, and growth.

With over two decades of experience and a nationwide network of UK data centres, we’re trusted by businesses across a range of sectors to protect critical assets, modernise IT environments, and accelerate digital transformation. Whether you’re optimising your existing setup or building for the future, our team is here to support your journey - every step of the way.

Team Size201-500 employees
WorkspaceHybrid
IndustryIT Services and IT Consulting
Location
United Kingdom
Websiteiomart.com
LinkedInLinkedIn

Top Benefits

  • Competitive salary
  • Flexible hybrid or remote working model
  • Professional development support
  • Certification support
  • Career progression

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?