Job title: Elastic SME (Outside IR35)
Job type: Contract
Emp type: Full-time
Pay interval: Hourly
Pay rate from: GBP £470.00
Pay rate to: GBP £570.00
Location: Farnborough
Job published: 06/01/2026
Job ID: 40542
Contact name: Emma Homann
Phone number: +441962442047
Contact email: emma@talentlocker.co.uk

Job Description

Elastic SME (SIEM)

Outside IR35 | Farnborough

 

Talent Locker are supporting a Defence and National Security consulting organisation and are recruiting for an experienced Elastic SIEM SME to support critical operational capability within a highly secure environment.

 

PLEASE NOTE – this role requires onsite delivery, and candidates must hold UK SC Clearance prior to appointment.

 

This contract sits within an operational security function where you will play a key role in shaping and ehancing how security data is collected, analysed and used to support mission outcomes. Working alongside engineering and operational teams, you’ll bring deep Elastic expertise to improve detection coverage, operational insight and response effectiveness.

 

You’ll fovus on strengthening SIEM capability through the development and optimisation of detection logic, ensuring reliable log ingestion into Elasticsearch and creating dashboards that provide meaningful visibility for security operations. The role also involves hands-on investigation of alerts, supporting triage activities, and continuously refining detections to reduce noise and improve accuracy (particularly within technical constrained environments).

 

Responsibilities will include;

 

  • Build and maintain detections rules within Elastic SIEM
  • Oversee log ingestion, parsing and enrichments to ensure high quality data
  • Develop and maintain Kibana dashboard to support operations
  • Monitor and investigate SIEM alerts and support incident triage
  • Improve detection fidelity by refining logic and reduce false positives
  • Work with stakeholders to align capability with operational priorities

 

Experience needed;

 

  • Hands on experience with Elasticsearch, Kibana, Elastic SIEM, ELK, Elastic stack etc.
  • Proven ability to work with log pipelines, data normalisations etc
  • Experience writing detections using KQL, EQL or similar
  • Demonstrable experience operating in restricted or secure environments
  • Has a sound understanding of security operations
  • Awareness and knowledge of adversary techniques and detection frameworks (including MITRE ATT&CK)
  • Supporting automation with some scripting capability (e.g. python/ bash)

 

To find out more or to apply, please send your CV to emma@talentlocker.co.uk