Skip to main content
AfterDuty

SIEM Engineer

Iomart · Leeds, West Yorkshire

Type
Full-time
Posted
7 days ago

Overview

Your investigative mindset and threat assessment skills translate to detection engineering.

About this role

What you'll be doing

As a SIEM Engineer at Atech, you will play a key role in designing, implementing, and optimising security monitoring solutions across a diverse range of customer environments. Working primarily with Microsoft Sentinel, Microsoft Defender, and the wider Microsoft Security ecosystem, you will help onboard customers into our Managed SOC service while supporting them in strengthening and maturing their overall security posture.

This role combines technical engineering, detection development, automation, and customer engagement. You will be responsible for building and maintaining high-quality detections, configuring data integrations, tuning alerting, and developing automations that improve both the effectiveness and efficiency of our Security Operations Centre (SOC). You will work closely with SOC Analysts, Security Consultants, Engineers, and customers to deliver innovative security solutions that help organisations identify, investigate, and respond to threats more effectively.

As part of a growing security practice, you will have the opportunity to shape the future of Atech's security services by contributing to detection engineering, automation initiatives, internal tooling, and service improvements. This is an excellent opportunity for someone who is passionate about cyber security, enjoys solving complex technical challenges, and wants to work with cutting-edge Microsoft security technologies.

Key Responsibilities

  • Design, implement, and maintain detections, analytics rules, workbooks, watchlists, and automations within Microsoft Sentinel.
  • Onboard new customers into Atech's Managed SOC service, including configuring integrations, data connectors, and monitoring capabilities.
  • Optimise and tune alerts to improve detection quality, reduce false positives, and enhance analyst efficiency.
  • Develop and maintain security monitoring content aligned to customer requirements and emerging threats.
  • Design and implement automation solutions using Microsoft Sentinel, Logic Apps, PowerShell, Python, and other supporting technologies.
  • Identify opportunities to improve and streamline security operations through automation and process improvement.
  • Support incident detection and response activities through the development of tooling, workflows, and detection capabilities.
  • Develop and maintain internal security tooling, scripts, and deployment pipelines.
  • Work collaboratively with SOC Analysts and Engineers to continuously improve security monitoring and operational effectiveness.
  • Contribute to technical designs, peer reviews, and security-focused projects across the wider business.
  • Create and maintain clear technical documentation, standards, processes, and procedures.
  • Produce technical reports, dashboards, and service summaries for customers and internal stakeholders.
  • Assist customers and colleagues in understanding and adopting Microsoft security technologies and best practices.
  • Stay current with emerging cyber threats, attack techniques, and advancements within the Microsoft Security ecosystem.
  • Participate in training, certifications, and continuous professional development to support your career growth and ensure Atech remains at the forefront of security detection and response.

We want to hear from you if you

  • Are UK-based with full right to work in the UK.
  • Have hands-on experience with Microsoft Sentinel, Microsoft Defender, or similar SIEM/SOC technologies.
  • Are passionate about cyber security and keeping up with emerging threats and attack techniques.
  • Have experience with KQL, PowerShell, Python, or other scripting and automation tools.
  • Enjoy solving complex technical challenges and improving processes through automation.
  • Can communicate confidently with both technical and non-technical audiences.
  • Thrive in collaborative environments and enjoy working with customers and colleagues.
  • Have an interest in detection engineering, threat hunting, security monitoring, and incident response.
  • Take ownership of your work, manage priorities effectively, and adapt in a fast-paced environment.
  • Are committed to continuous learning, professional development, and knowledge sharing.
  • Have experience using AI tools such as Microsoft Copilot to enhance productivity and streamline workflows.
  • Hold Microsoft security certifications such as SC-200, AZ-500, or SC-300.

Bonus Points If You

  • Have experience with Azure Logic Apps, Azure Functions, Terraform, Bicep, or Infrastructure as Code (IaC).
  • Have worked within a SOC, MSSP, or Managed Security Services environment.
  • Have experience with Detection-as-Code or Content-as-Code practices.
  • Have exposure to threat intelligence, threat hunting, malware analysis, or purple team activities.
  • Have integrated third-party security products and data sources into Microsoft Sentinel.
  • Have implemented AI capabilities, such as Copilot, within automations, workflows, or internal tooling.
  • Contribute to security tooling, open-source projects, technical content, or security research.

What's in it for me?

  • Competitive salary and benefits package.
  • Flexible hybrid or remote working model
  • Exposure to a broad range of cyber security technologies and customer environments.
  • Opportunity to work on complex and high-impact security incidents.
  • Ongoing learning, certification and professional development support.
  • Clear career progression within a growing cyber security practice.
  • A collaborative and supportive team environment where knowledge sharing is encouraged.
  • The opportunity to influence SOC maturity, service innovation and security outcomes for our customers.

Who you'll be doing it for

Atech part of the Iomart Group is a highly accredited Microsoft Partner who delivers transformed technology with managed services. Our team of certified Microsoft experts align with your team to deliver an excellent service tailored to your individual needs, 24/7/365.

Our services support 25,000 users globally and proactively monitor 45,000+ devices in key areas:

  • Azure infrastructure managed service
  • Modern Workplace: Office 365, Microsoft 365, and Azure Virtual Desktop
  • Managed Security and SOC with Microsoft Defender, Sentinel

What to do next

Please click apply if you like the sound of this role. If you do not have an up to date CV or want to have a chat about the role first, please contact us on careers@iomart.com.

We’re an equal opportunities employer and want our vacancies to be available to all, so if you need us to make any reasonable adjustments during the process then just let us know.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Leeds

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Your experience with digital evidence handling and investigative reporting maps directly onto SOC triage and incident documentation.

    Posted 11 days ago

  • Full-time

    Your incident management and digital forensic investigation experience from policing transfers directly to cyber incident response.

    Posted 14 days ago

  • Lead Cyber Security Monitoring

    Driver and Vehicle Standards Agency (DVSA) · Leeds

    Full-time

    Your experience in digital forensics, evidence handling, and incident command from policing maps directly to this SOC lead role.

    Posted 16 days ago

  • Operational and Cyber Resilience Lead

    Financial Conduct Authority · Leeds

    Full-time

    Your incident command and contingency planning experience directly applies to assessing firms' operational resilience and cyber incident response.

    Posted 23 days ago