Security Complex Engineering Specialist (Snowhill, Birmingham, United Kingdom)Why this job mattersThis role will play a vital part in the protection of BT. Responsible for working across engineering teams, threat analysts and key stakeholders you will be responsible for utilising our security engineering capabilities to regularly inspect and improve our threat intelligence and threat hunting capabilities.If you’re passionate about cloud security and want to be at the forefront of innovation, this role is for you. This role is hybrid (3 days in office) and can be based in one of the following offices: Birmingham, Manchester, Ipswich (Ipswich only applicable to existing BT employees)What you’ll be doingYou’ll be part of a holistic security engineering team, implementing BT-wide, multi-system, complex design, holistic use case development and management. This will require close collaboration with teams responsible for specific security capabilities in our federated security engineering approach. Core to this are the following accountabilities:Designing, implementing and managing security detection use cases across a range of technologies to ensure timely alerting of security events and incidents to Security Operations staff.Responding to specific threats and intelligence to enable insight from security capabilities at the pace of incidents in support of incident technical bridges.Continuously improving threat detection capabilities by tuning and optimising existing use cases and retiring use cases no longer providing value.Collaborate regularly across Protect BT Group stakeholders and engineering teams to quickly respond to new use casesAct as a security use case subject matter expert, responding to requests, working with wider teams, making priority decisions and deciding the best action to regularly advance our threat detection capabilitiesProactively adapting and maintaining threat intelligence and detection capabilities to ensure we provide the best possible environment to keep BT safe.Enhance data enrichment by integrating threat intelligence feeds and contextual information.Contribute to security engineering projects, transitions, and transformations.Work closely with security operations and associated security incident response systemsStay informed about emerging threats and security best practices.Drive end to end automation across the eco system of security capabilities to drive efficiency and speed of response to cyber threats.Collaboration with commercial security teams where BT consumes our commercial propositions for internal use.Skills Required for the RoleCommunication:Able to effectively communicate across multiple engineering teamsCoordinate across multiple teams to work towards a common goalCollaborate with a wider range of stakeholders, reporting progress and adapting quickly to feedbackDelivery:Responsible for the delivery and in life management of complex use casesCoordinating rapid responses to changes in the threat landscapeWorking across multiple stakeholders to ingest, parse, index and consume data feeds required to evolve our threat hunting abilityDrive automation of data ingestion, transformation and loading tasksDesign:Responsible for designing complex security use case detection logicDocumenting design decisions and communicating with engineering teamsProactively understanding how we can get more value from SIEM and other tooling to continually mature our capabilitiesDesign, develop, and maintain data pipelines using Logstash, part of the Elastic Stack.Data Cleaning and Enrichment with Elasticsearch:Utilize Elastics for efficient data storage and retrieval.Implement data validation, enrichment, and indexing.Collaborate with data analysts to create meaningful search experiences.Database Architecture and Scaling with Elastic:Optimize data storage and retrieval mechanisms within Elastic clusters.Design and Implement sharding, replication, and index management strategies.Security and Compliance with Elastic Security:Set up access controls, authentication, and encryption using Elastic Security features.Ensure compliance with data protection regulations.Performance Tuning with Elastic and Logstash:Fine-tune query performance using Elastic indices and mappings.Monitor Logstash pipelines and optimize resource utilization.Kibana Visualization and Monitoring:Leverage Kibana for data visualization, dashboards, and real-time monitoring.Create custom visualizations to track data quality metrics and system performance.Kafka integrationExperience Required for the RoleMANDATORYExperience working in the threat intelligence / threat hunting environmentKnowledge of working on a SIEM/big data/ threat hunting capabilityExperience in cyber security implementation and supportKnowledge of security best practices, regulatory requirements and standardsELK stack awarenessKnowledge of the MITRE ATT&CK frameworkPREFERREDExperience supporting complex cyber security or IT projects.Actively worked on a SIEM solution and experience of use case detection/creationDetailed knowledge of Elastic architectureBenefitsOn target 10% on target bonusBT Pension scheme, minimum 5% Employee contribution, BT contribution 10%From January 2025, equal family leave: receive 18 weeks at full pay, 8 weeks at half pay and 26 weeks at the statutory rate. It’s for all parents, no matter how your family is made up.Enhanced women’s health support: including help with menopause symptoms, cancer screenings, period care and more.25 days annual leave (not including bank holidays), increasing with service24/7 private virtual GP appointments for UK colleagues2 weeks carer’s leave World-class training and development opportunitiesOption to join BT Shares Saving schemes.About usBT Group was the world’s first telco and our heritage in the sector is unrivalled. As home to several of the UK’s most recognised and cherished brands – BT, EE, Openreach and Plusnet, we have always played a critical role in creating the future, and we have reached an inflection point in the transformation of our business. Over the next two years, we will complete the UK’s largest and most successful digital infrastructure project – connecting more than 25 million premises to full fibre broadband. Together with our heavy investment in 5G, we play a central role in revolutionising how people connect with each other. While we are through the most capital-intensive phase of our fibre investment, meaning we can reward our shareholders for their commitment and patience, we are absolutely focused on how we organise ourselves in the best way to serve our customers in the years to come. This includes radical simplification of systems, structures, and processes on a huge scale. Together with our application of AI and technology, we are on a path to creating the UK’s best telco, reimagining the customer experience and relationship with one of this country’s biggest infrastructure companies. Change on the scale we will all experience in the coming years is unprecedented. BT Group is committed to being the driving force behind improving connectivity for millions and there has never been a more exciting time to join a company and leadership team with the skills, experience, creativity, and passion to take this company into a new era.A FEW POINTS TO NOTE:Although these roles are listed as full-time, if you’re a job share partnership, work reduced hours, or any other way of working flexibly, please still get in touch.We will also offer reasonable adjustments for the selection process if required, so please do not hesitate to inform us.DON'T MEET EVERY SINGLE REQUIREMENT?Studies have shown that women and people who are disabled, LGBTQ+, neurodiverse or from ethnic minority backgrounds are less likely to apply for jobs unless they meet every single qualification and criteria. We're committed to building a diverse, inclusive, and authentic workplace where everyone can be their best, so if you're excited about this role but your past experience doesn't align perfectly with every requirement on the Job Description, please apply anyway - you may just be the right candidate for this or other roles in our wider team.