Cyber Data Engineer - #2162990
mthree
Cyber Data Engineer
Location: Glasgow
mthree is hiring a Cyber Data Engineer to work with a tier-one global investment bank in Glasgow. You'll join a globally distributed squad that delivers and runs the bank's security analytics platforms on Splunk and Elasticsearch. Their main stakeholders are the cyber teams, including security response, investigations and insider threat.
The squad needs someone to help maintain and develop these platforms. It's a demanding role with a steep learning curve, but you'll be working within a supportive team, and it's a strong opportunity to build your technical skills in a security setting.
The Role
You'll look after the Splunk and Elasticsearch platforms, onboarding new data, automating configuration with tools such as Terraform and Ansible, tuning performance, and acting as a senior escalation point when things go wrong.
Responsibilities
- Onboard new data sources into Splunk and Elasticsearch, with the right field extractions
- Build automation tools that integrate with in-house configuration management frameworks and APIs
- Advise internal clients and stakeholders on using the platforms
- Identify and implement tuning to improve platform performance
- Act as a top-level escalation point, troubleshooting complex issues and working with other infrastructure teams to resolve them
Required Experience
- 1–2 years of hands-on experience with Splunk and/or Elasticsearch
- Infrastructure automation experience using Terraform and Ansible, with Python for integration and scripting
- Solid understanding of operating systems and networking, including Linux/Unix administration, HTTP and encryption
- Good understanding of version control, build and deployment tools within DevOps SDLC practices (Git, Jenkins, Jira)
- Strong analytical and troubleshooting skills
- Clear written and verbal communication
- Familiarity with Agile, particularly Kanban
Desirable Experience
- Building data pipelines on a major cloud provider (GCP, Azure or AWS)
- Administrator or architect level certification in Splunk or Elasticsearch
- Writing and testing field extractions using regular expressions
- Familiarity with cybersecurity concepts, event types and monitoring requirements
About mthree
This role is through mthree's Expert programme. You'll be employed directly by mthree and deployed full time with one client, working as part of their team on their projects. Throughout the assignment you'll have ongoing support from mthree, and where applicable there is a clear route to permanent employment with the client.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Senior Software Engineer
Wireman