CYBER DEFENCE - SIEM CONTENT DEVELOPMENT SPECIALIST - VOIS
Who we are
As the largest shared services organisation in the global telco industry with 30,000 FTE, our portfolio of next-generation solutions and services are designed in partnership with customers across Vodafone Group, local markets, and partner markets to simplify and drive growth. With our strategic partner Accenture, we work alongside our Vodafone customers, other Telco and tech companies to drive transformation, meet the challenges of our industry and ensure we stay relevant and resilient. This partnership is a unique, industry-first model which brings together the best of in-house and 3rd party capability.
We work with customers across 28 countries from 10 VOIS locations: Albania, Egypt, Hungary, India, Romania, Spain, Turkey, UK, Germany, Ireland, and with a network of teams in Czech Republic, Italy, Greece, and Portugal.
#VOIS #BeUnrivalled #CreateTheFuture
About this Role
What you’ll do
- Design, develop and fine-tune detection rules and use cases across existing and new SIEM platforms, with a strong focus on Elastic (ELK) and other leading SIEM technologies.
- Lead and contribute to security content engineering initiatives, applying secure software development lifecycle (SDLC) and agile practices.
- Analyse attacker behaviour, threat intelligence, MITRE ATT&CK techniques and adversary tooling to create indicator-based and behavioural detections.
- Support and, where required, lead threat response workflows and playbook creation, ensuring seamless integration with CSOC operations.
- Collaborate closely with log source owners, engineering teams and stakeholders to understand telemetry, risks and operational requirements, translating them into effective detection content.
- Deliver security reporting, advisories and post-incident analysis, converting lessons learnt into measurable improvements in detection and response.
- Maintain clear documentation, including detection logic, workflows and operational playbooks, to support consistent CSOC operations.
Who you are
- An experienced cyber security professional with a strong background in SOC operations, SIEM content development, threat hunting or security engineering.
- Skilled in SIEM technologies, with hands-on experience in Elastic/ELK and working knowledge of platforms such as ArcSight, Microsoft Sentinel, Splunk or Chronicle.
- Comfortable working with cloud and endpoint telemetry across environments such as AWS, GCP and Microsoft security tooling.
- Technically confident, with experience in programming or scripting (for example Python, SQL, JavaScript, PowerShell, KQL or ES|QL) and strong capability in regular expression development.
- Knowledgeable in security frameworks and threat models, including MITRE ATT&CK, cyber kill chain concepts and advanced persistent threat strategies.
- Analytical, collaborative and able to work independently, making informed decisions while building strong relationships across the security community.
Not a perfect fit?
What's in it for you
-
The opportunity to work at the heart of Vodafone’s global cyber defence capability, protecting customers and critical services at scale.
-
Exposure to complex, enterprise-level security environments and modern SIEM, EDR and XDR technologies.
-
A collaborative, inclusive environment that values continuous improvement, learning and innovation.
-
The chance to influence detection strategy and operational effectiveness across multiple markets.
What skills you will learn
- Advanced SIEM content engineering and optimisation techniques across multiple platforms.
- Deeper expertise in behavioural detection, threat modelling and adversary simulation.
- Practical application of secure software development practices within cyber defence operations.
- Enhanced stakeholder engagement and communication skills within a global security organisation.
VOIS Equal Opportunity Employer Commitment
Join Us
We challenge and innovate in order to connect people, businesses, and communities across the world. Delighting our customers and earning their loyalty drive us, and we experiment, learn fast and get it done, together.
With us, you can be truly be yourself and belong, share inspiration, embrace new opportunities, thrive, and make a real difference.
Alert
Follow us on social media and #StayConnected
- You can also chat with our employees to learn more about our projects: Employee Chat