Job Search and Career Advice Platform

Enable job alerts via email!

Lead SIEM Engineer

Morgan Stanley

Glasgow

On-site

GBP 70,000 - 90,000

Full time

30+ days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading global financial services firm in Glasgow is seeking an experienced Lead SIEM Engineer to join their Cyber Response Platforms team. The ideal candidate should possess over 10 years of cyber-security expertise, particularly in network defense and incident response. Responsibilities include leading a team to enhance cybersecurity detection and response, developing advanced detection logic, and ensuring compliance with industry standards. The firm offers competitive benefits and promotes a diverse and inclusive work environment.

Benefits

Comprehensive employee benefits
Opportunities for career mobility

Qualifications

  • Minimum of 10 years of experience in cyber detection engineering or incident response.
  • Strong understanding of network security and endpoint detection.
  • Experience with SIEM rule tuning and correlation logic.

Responsibilities

  • Lead a team to improve cyber-security detection and response.
  • Develop analytics in Splunk or Elastic Search for actionable alerts.
  • Create security metrics and reports for security posture.

Skills

Cyber detection engineering
Network security
Incident response
SIEM management
Unix/Linux command-line
Communication skills
Organizational skills

Tools

Splunk
Elastic Search
Python
Job description

Lead SIEM Engineer role at Morgan Stanley

Overview

Cyber Response Platforms is looking for an experienced (10+ years) cyber-security professional to join their team as a SIEM lead. Our ideal candidate has hands-on experience in computer network defence working either in a Security Operations Center or Cyber Incident Response Team.

You will lead a team of technologists and cyber-security professionals that are dedicated to improving the coverage, quality and automation of cyber-security detection and response.

Primary Responsibilities
  • Supervise and govern the development of analytics in Splunk (SPL) or Elastic Search (EQL) to detect actionable security alerts
  • Develop and fine-tune advanced detection rules, alerting mechanisms, and use cases to identify and respond to sophisticated security threats
  • Create comprehensive security metrics, reports, dashboards, providing detailed insights into the organization\'s security posture
  • Ensure that the SIEM solution complies with global regulatory standards and industry best practices
  • Mentor and guide SIEM engineers, fostering a culture of continuous learning and development within the team
  • Participate in the development of the organization\'s security strategy and contribute to its execution
  • Monitor and support SIEM platforms to ensure security and stability of SOC infrastructure
Additional Leadership Responsibilities
  • Provide day-to-day leadership and oversight for the SIEM engineering team, ensuring alignment with strategic goals and operational priorities
  • Facilitate regular team standups, retrospectives, and planning sessions to promote transparency and accountability
  • Coach team members on technical and professional growth, offering constructive feedback and career development support
  • Champion a collaborative and inclusive team culture that encourages innovation, ownership, and continuous improvement
  • Identify and address skill gaps through targeted training, mentoring, and knowledge-sharing initiatives
  • Act as a point of escalation for technical challenges and team dynamics, resolving issues with empathy and decisiveness
  • Collaborate with cross-functional teams to ensure seamless integration of SIEM capabilities into broader cyber response workflows
Essential Skills and Experience
  • Minimum of 10 years of experience in cyber detection engineering or incident response
  • Strong understanding of network security, endpoint detection and computer forensics
  • Experience in the creation and management of detection logic in SIEMs (e.g. Elastic Search, Splunk, ArcSight, Microsoft Sentinel)
  • Experience with SIEM rule tuning, correlation logic, alert de-duplication and false-positive reduction techniques
  • Strong knowledge of exploitation techniques (e.g. MITRE ATT&CK) and use-case development
  • Thorough TCP/IP and protocol experience (OSI L2-L7, DNS, HTTP, REST, SOAP)
  • Highly experienced with Unix/Linux command-line tools and shell scripting
  • Strong communication, task management and organizational skills
Desirable Skills
  • Experience developing automations in SOAR (e.g. Palo Alto XSOAR, SumoLogic, Swimlane)
  • Experience with Indicators of Compromise (e.g. YARA rules, STIX and TAXII)
  • Hands-on experience with a query language (e.g. Splunk SPL, Elastic EQL, SQL)
  • Experience with streaming data frameworks (e.g. Kafka, NiFi, Spark)
  • Experience with CI/CD technology (e.g. Jenkins, GitLab CI, GitHub Actions)
  • Experience in the administration of systems or security controls
  • Intermediate experience developing scripts in Python
What You Can Expect From Morgan Stanley

We are committed to maintaining the first-class service and high standard of excellence that have defined Morgan Stanley for over 89 years. Our values—putting clients first, doing the right thing, leading with exceptional ideas, committing to diversity and inclusion, and giving back—guide the decisions we make every day to do what\'s best for our clients, communities and more than 80,000 employees in 1,200 offices across 42 countries. You\'ll work with the best and brightest in an environment that supports and empowers you. Our teams are relentless collaborators and creative thinkers, driven by diverse backgrounds and experiences. We offer attractive and comprehensive employee benefits and opportunities to move across the business for those who show passion and grit.

To learn more about our offices across the globe, please copy and paste https://www.morganstanley.com/about-us/global-offices into your browser.

Regulatory and Working Arrangements

Certified Persons Regulatory Requirements: If this role is deemed a Certified role and may require the role holder to hold mandatory regulatory qualifications or the minimum qualifications to meet internal company benchmarks.

Flexible work statement: Morgan Stanley empowers employees to have greater freedom of choice through flexible working arrangements. Speak to our recruiting team to find out more.

Morgan Stanley is an equal opportunities employer. We work to provide a supportive and inclusive environment where all individuals can maximize their full potential. Our workforce reflects a variety of backgrounds, talents, perspectives, and experiences.

Position Details
  • Seniority level: Mid-Senior level
  • Employment type: Full-time
  • Job function: Engineering and Information Technology

Referrals increase your chances of interviewing at Morgan Stanley by 2x

Sign in to set job alerts for “Lead Engineer” roles.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.