Jobs and Careers
GR
Senior Security Detection Engineer
Great-West LifecoIrelandfull_timeVerifiedPosted 4 Jan 2025
About the role
<ul>
<li><span>Full Time <b>Permanent </b>position</span></li>
<li><span>Hybrid role based in our City Centre offices</span></li>
</ul>
<p><br/>
<span><b>What we offer</b><br/>
We have embraced a hybrid working model for most of our positions, which means that you can enjoy a balanced approach of working from home for part of the week and working from the office for the remainder of the week.</span></p>
<p><br/>
<span>We offer a comprehensive benefits package including competitive salaries and bonuses, robust Learning and Development support, excellent Defined Contribution pension and comprehensive Wellbeing initiatives and support to name but a few. </span></p>
<p><br/>
<span>Further details on our benefits package can be accessed here <a href="https://life-careers.com/irishlife/content/Benefits/?locale=en_GB">Benefits (life-careers.com)</a></span><br/>
</p>
<p> </p>
<h2><b>Role Overview</b></h2>
<p><span>We are seeking an experienced Senior Technical Specialist (Detection Engineer) to join the Endpoint Security Team as a Subject Matter Expert, focusing on SIEM management, Log source onboarding, and continuous improvement of security monitoring coverage and capabilities. The Senior Technical Specialist will be a key player in driving the operational excellence of our Security Information and Event Management (SIEM) systems. The Senior Technical Specialist will help mature the detection processes and capabilities to better defend our environments. This role will support our global SOC by providing high-fidelity signals and technical analysis aimed to detect adversary tactics, techniques, and behaviours. <br/>
The Endpoint Security team report to the Head of Security Operations, providing security services to the European group of companies. The Senior Technical specialist will report to the Endpoint Security Manager within Central Security Services. <br/>
The candidate will report to the Endpoint Security Manager and work closely with other security professionals to ensure that our SIEM platform and log sources are effectively managed, continuously optimised and aligned with the organisation’s security posture. </span><br/>
</p>
<h2><b>Team Background</b></h2>
<p><span>The Endpoint Security Team sits within our Central Security Services department and reports to the Head of Security Operations. This team has oversight/responsibility for:<br/>
• Antivirus<br/>
• Endpoint Detection and Response (EDR)<br/>
• Security Incident Event Monitoring (SIEM)<br/>
• Privileged Access Management (PAM)<br/>
• Database Security<br/>
• Endpoint Security Metrics & KPI’s<br/>
• Endpoint Security Strategy & Roadmaps</span></p>
<h2><b>What you will help us to achieve</b></h2>
<p><span>• Build new detection capabilities based upon research, analysis of threat actor methodologies, and testing of new attack techniques for cloud-based platforms in Azure, AWS, GCP and other SaaS providers. <br/>
• Serve as a Subject Matter Expert (SME) for SIEM management, log source onboarding, and SIEM platform optimisation. <br/>
• Design, deploy, and maintain SIEM agents/systems across the environment to meet Service Level Agreements (SLAs) and operational requirements. <br/>
• Onboard and integrate new log sources into SIEM, ensuring compliance with organisational security policies and regulatory requirements.<br/>
• Contribute to development and implementation of use cases and correlation rules to detect and respond to security incidents. <br/>
• Perform periodic audits and health checks of SIEM infrastructure, including performance tuning, system upgrades, and patch management. <br/>
• Collaborate with cross-functional teams to ensure successful integration of log sources from various network devices, application, and security tools. <br/>
• Participate in incident detection and response activities, acting as a key member of the Critical Incident Response Team during major incidents. <br/>
• Proactively identify opportunities to automate, optimise, and enhance the SIEM platform and overall security operations. <br/>
• Actively work with our threat operations and engineering team to enhance the processes that support the SOC team’s mission.<br/>
• Mentor junior engineers and provide training on SIEM technologies and security event management practices. <br/>
• Production of quality documentation and training material.<br/>
• The main point of contact and the highest escalation point to the SIEM service.<br/>
• Ensure adherence with risk management programmes.<br/>
• Security Infrastructure Capacity Planning & Management for the SIEM service.<br/>
• Attend project meetings and maintain strong relationships.<br/>
• Identify opportunities or emerging demands and plan for them.<br/>
• Ensure that business risks are identified, and adequate controls are in place. <br/>
• Ensure alignment with industry best practices, compliance standards, and frameworks such
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s