SPLUNK Engineer

Sopra Steria
Hemel Hempstead, HP1 1EW, United Kingdom
Last month
£64,000 – £96,000 pa

Salary

£64,000 – £96,000 pa

Job Type
Permanent
Work Pattern
Full-time
Work Location
On-site
Seniority
Senior
Security Clearance
Required
Posted
24 Apr 2026 (Last month)

Benefits

£5400 Car Allowance 25 days annual leave with the option to buy additional days Private health care Life assurance Pension Generous flexible benefits fund

We are looking for an experienced Splunk Engineer to lead the design, deployment and optimisation of enterprise-scale security monitoring platforms.

This is a hands-on technical role, suited to someone with strong Splunk Enterprise and Splunk Enterprise Security experience, who can take ownership of platform engineering, data ingestion, detection content and performance tuning across complex client environments.

This is a key technical leadership role, responsible for ensuring the right tooling, controls and processes are in place to help protect and monitor our clients’ environments.

The opportunity is ideally suited to someone with deep hands-on experience deploying, managing and optimising Splunk Enterprise and Splunk ES in large, complex environments. In return, the role offers the chance to broaden your capability and gain deeper experience in Elastic Security, with support and training available to help build your expertise further.

You will work closely with cross-functional teams to assess risk, design effective security controls and define testing requirements. You will champion security by design, promote engineering excellence and act as a trusted advisor to clients, helping them understand their security challenges and implement practical, effective solutions to strengthen their security posture.

This is an excellent opportunity to deepen your hands-on cybersecurity expertise while making a meaningful impact across both client and organisational security.

You do need to hold active DV Clearance.

Office based in Hemel HBempstead.

What you will be doing:

  • Lead the deployment, management and optimisation of Splunk Enterprise and Splunk ES platforms in large, complex environments.
  • Design, implement and maintain data pipelines, including log ingestion, enrichment and schema standardisation.
  • Develop and tune security detection content, translating threat intelligence and TTPs aligned to MITRE ATT&CK into actionable, high-value alerts.
  • Manage the full detection content lifecycle: design, test, deploy, monitor, tune and retire, using version control and rollback processes.
  • Automate workflows and platform configurations using CI/CD, SOAR, scripting and Infrastructure as Code tools such as Terraform and Ansible.
  • Ensure platform performance, stability and resilience through capacity planning, high availability, disaster recovery and proactive monitoring.
  • Provide technical leadership and guidance to internal teams and clients on security monitoring strategy and best practice.

What you will bring:

  • Proven experience deploying and managing Splunk at enterprise scale.
  • Strong hands-on knowledge of SIEM engineering, including indexing, parsing, onboarding and performance tuning.
  • Experience designing and optimising detection content, including MITRE ATT&CK-aligned use cases and alert tuning to reduce noise.
  • Good understanding of data pipeline engineering, log enrichment, data quality and large-scale ingestion architectures.
  • Strong knowledge of SPL; experience with KQL and EQL would be beneficial, but is not essential.
  • Experience with automation and Infrastructure-as-Code within security monitoring or SIEM environments.
  • Solid understanding of SIEM platform operations, including clustering, scaling, high availability, disaster recovery and performance optimisation.
  • Strong problem-solving skills and a proactive approach to improving security operations.
  • An interest in developing expertise in Elastic Security, with support and training available as part of the role.

If you are interested in this role but not sure if your skills and experience are exactly what we’re looking for, please do apply, we’d love to hear from you!

Employment Type: Full Time, Permanent

Location: Hemel Hempstead

Security Clearance Level: DV Cleared

Internal Recruiter: Jane

Salary: Competitive, depending on experience

Benefits: £5400 Car Allowance, 25 days annual leave with the option to buy additional days, private health care, life assurance, pension, and generous flexible benefits fund

?Loved reading about this job and want to know more about us?

Sopra Steria’s Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client’s goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK’s most complex safety- and security-critical markets.

Related Jobs

View all jobs

Senior Security Engineer

Bridewell Cardiff, United Kingdom
Hybrid

SOC Engineer

Searchability NS&D Watford, United Kingdom
£55,000 – £65,000 pa

SOC Engineer

Searchability NS&D Farnborough, GU14 7JT, United Kingdom
£55,000 – £65,000 pa

Senior Detection Engineer

Sopra Steria Farnborough, GU14 7JT, United Kingdom
£55,000 – £65,000 pa

Senior SOC Engineer

Sopra Steria Hemel Hempstead, HP1 1EW, United Kingdom
£65,000 – £75,000 pa

Application Security Engineer

Health Hero W1T1Af, W1T 1AF, United Kingdom

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Where to Advertise Cyber Security Jobs in the UK (2026 Guide)

Where to advertise cyber security jobs UK in 2026: the specialist boards, communities and channels that reach offensive, defensive and GRC security talent. The candidate pool is small, heavily vetted and in high demand across government, financial services, critical national infrastructure and the private sector simultaneously. Many of the strongest candidates hold active security clearances, are not actively job-searching through general platforms, and move primarily through specialist networks and trusted referrals. General job boards reach a broad audience but lack the specificity that security professionals expect. Specialist platforms, government-affiliated channels and cleared candidate networks each serve a different part of the market. This guide, published by CybersecurityJobs.tech, covers where to advertise cyber security roles in the UK in 2026, how the main platforms compare, what employers should expect to pay, and what the data says about hiring across different role types.

Cyber Security Jobs UK 2026: What to Expect Over the Next 3 Years

Cyber Security Jobs UK 2026: roles, salaries and the threat intelligence, cloud security and zero-trust hiring trends shaping UK cyber careers. Cyber security is one of the few sectors where demand for talent has never once dipped. Every major technological shift of the past decade — cloud migration, remote working, AI adoption, the proliferation of connected devices — has expanded the attack surface that security professionals are expected to defend. And every expansion of that attack surface has generated more jobs. But the cyber security jobs market of 2026 is not simply a larger version of what it was three years ago. It is a structurally different market. The threats have evolved, the technologies used to combat them have changed, the regulatory environment has tightened considerably, and the roles being created reflect all of that. A job seeker who understands only the cyber security landscape of 2023 is already working with an outdated map. The candidates who will thrive over the next three years are those who understand where the sector is heading — which specialisms are attracting the most investment, which technologies are reshaping defensive and offensive security practice, and how the definition of a cyber security professional is broadening well beyond the traditional image of a network defender in a SOC. This article breaks down what the UK cyber security jobs market is likely to look like through to 2028 — covering the titles emerging right now, the technologies driving employer demand, the skills that will matter most, and how to position your career ahead of the curve.