Contract Spy
Farnborough, England, United Kingdom
We are seeking an experienced Elastic SIEM Subject Matter Expert (SME) to support NESTOR operations.
This role involves developing and refining threat detection capabilities, managing log ingestion, and creating operational dashboards.
The ideal candidate will be adept at working in constrained environments and applying Elastic tools creatively to meet mission needs.
Key Responsibilities
Develop, tune, and optimize SIEM detection rules to identify threats and reduce false positives
Manage log ingestion pipelines and ensure reliable data flow into Elasticsearch
Design and maintain Kibana dashboards for operational visibility
Triage SIEM tickets and investigate alerts to determine root causes
Continuously improve detection logic to enhance signal-to-noise ratio
Collaborate with NESTOR teams to align SIEM capabilities with operational goals
Required Skills and Experience
Strong hands-on experience...