Available now — immediate start possible

Hire a Senior SIEM Engineer Directly. No Agency. No Markup.

Adam Musa is a platform-agnostic SIEM specialist with 10+ years of enterprise experience across Sentinel, QRadar, Splunk, and Elastic. Available for direct B2B contracts globally via UK Ltd or US LLC. You keep the agency margin.

Platform expertise

Expert across all four major SIEM stacks

Most contractors specialise in one platform. Adam brings senior-level expertise across all four — whichever SIEM your environment runs, he can hit the ground running from day one.

8+ years · Primary platform

Microsoft Sentinel

Adam led Microsoft Sentinel implementation and optimisation at Charles River Associates, building KQL analytics, SOAR workflows, Power BI security dashboards, and operational automation. He also delivered Sentinel and SOAR work at PA Consulting, including MFA, Conditional Access, incident response coordination, and SOC 2 / ISO 27001 aligned controls. His Sentinel work connects detection engineering, Defender XDR telemetry, and practical incident response rather than treating the SIEM as a standalone tool. This makes him useful for greenfield builds, noisy existing deployments, and mature environments that need senior tuning.

KQL rulesLogic AppsSOARDefender XDRGreenfield builds
6+ years · Primary platform

IBM QRadar

Adam used IBM QRadar as a Tier 3 SOC escalation lead at IBM, investigating high-severity incidents and tuning correlation rules in enterprise environments. His QRadar work included offence investigation, log source analysis, threat hunting, and escalation support across network, endpoint, and cloud telemetry. The value is not just knowing the interface; it is knowing how QRadar alerts behave during a real incident and how to improve the signal over time. He can support both operational triage and engineering improvements for teams already running QRadar.

Correlation rulesOffence investigationLog sourcesCarbon BlackTier 3 escalation
5+ years · Primary platform

Splunk ES

Adam's Splunk experience comes from enterprise incident response work at Ford Motor Company, including threat hunting, digital forensics, malware analysis, and SOAR playbooks in Splunk Phantom. He has worked with detection workflows where Splunk sits alongside endpoint tools such as CrowdStrike, FireEye HX, and Carbon Black. That background is useful when Splunk ES needs practical detection logic, dashboards, and incident workflows that analysts can actually use. He can bridge engineering and response so SPL detections support real investigations.

SPL detectionPhantom SOARDashboardsLog pipelinesThreat hunting
4+ years · Primary platform

Elastic / Kibana

Adam led Elastic Security detection engineering at BT, working on Logstash pipelines, EQL detection rules, MITRE ATT&CK aligned use cases, and data quality across multi-cluster environments. Elastic work often fails because pipelines, indexing, and detection logic are treated separately; Adam's experience covers all three. He can help teams improve Elastic visibility, tune rules, and resolve ingestion problems that weaken security monitoring. This is especially valuable for organisations using Elastic as a flexible but engineering-heavy SIEM stack.

EQL rulesLogstashElasticsearchFleet & BeatsKibana dashboards

Employment history

Enterprise track record

Jan 2026 – Mar 2026

Senior SIEM Engineer

BT — UK

Led Elastic Security detection engineering at enterprise scale. Designed Logstash pipelines, built EQL detection rules aligned to MITRE ATT&CK, resolved data quality issues across multi-cluster environments.

ElasticEQLLogstashMITRE ATT&CKGitLab

May 2024 – Dec 2025

Sentinel SIEM Engineer

Charles River Associates — USA (Remote)

Led Sentinel implementation and optimisation. Designed SOAR automation workflows, built Power BI security dashboards, delivered phishing simulation campaigns, automated operations using Python and PowerShell.

SentinelKQLSOARPower BIPythonPowerShell

Oct 2023 – Apr 2024

CSIRT Lead

Hilti — Switzerland

Led enterprise MDE deployment across global endpoints. Built Defender XDR detections and automated response — reducing IR time by 40%. Implemented Azure Logic Apps automation.

SentinelDefender XDRMDELogic AppsIntuneZero Trust

Nov 2022 – Sep 2023

CSIRT Lead / SOC Engineer

PA Consulting — UK

Led Sentinel implementation delivering SIEM and SOAR. Designed MFA and Conditional Access policies, coordinated high and critical incident response, delivered SOC 2 and ISO 27001 aligned controls.

SentinelEntra IDDefenderSOC 2ISO 27001SOAR

Nov 2021 – Nov 2022

Tier 3 SOC Analyst

IBM — UK

Tier 3 escalation lead using IBM QRadar. Led high-severity incident investigations, tuned correlation rules, conducted threat hunting across network, endpoint, and cloud telemetry.

QRadarTier 3Threat huntingSOARIncident response

Jul 2020 – Nov 2021

Incident Response Analyst — Tier 3 SOC

Ford Motor Company

Advanced incident response and digital forensics using EnCase and Volatility. Led threat hunting using CrowdStrike and FireEye HX, developed SOAR playbooks in Splunk Phantom, conducted malware analysis.

SplunkCrowdStrikeEnCaseVolatilityCarbon BlackSOAR

Dec 2018 – Sep 2019

Senior SIEM Engineer

BT — UK

Led SIEM migration from ArcSight to McAfee for the Emergency Services Network (ESN). Developed and tuned detection use cases, managed log source onboarding, acted as Network Security Architect SME.

McAfee SIEMArcSightESNDetection engineeringWAF

Certifications

Qualifications & credentials

GIAC Certified Incident Handler (GCIH)

GIAC · 2023

ISO 27001 Certified ISMS

2014

GCTI

SANS / IBM · 2018

CompTIA Security+

2017

Microsoft Azure Security Engineer

In progress · 2025

White Hat Hacking

2013

NSE 2

Fortinet · 2020

MSc Information Security

Bedfordshire · 2013 (Merit)

Global availability

Where Adam works and how

United Kingdom

iCoreFusion Ltd

Remote · Hybrid · Onsite

Outside IR35 · rate on request

United States

iCoreFusion LLC

Remote only · Corp-to-Corp

Corp-to-Corp · rate on request

Canada

iCoreFusion LLC

Remote only · B2B

Rate on request

Australia

iCoreFusion Ltd / LLC

Remote only · B2B

Rate on request

Europe

iCoreFusion Ltd

Remote only · B2B

Rate on request

Middle East

iCoreFusion Ltd

Remote or onsite

Tax-free package · negotiable

How to engage

Getting started — four steps

  1. 1

    Send a direct message

    Email hello@icorefusion.com or message on LinkedIn with a brief description of the role, platform, location, and expected duration. No lengthy forms. No agency involved. Adam responds personally.

    Response within 4–8 business hours

  2. 2

    30-minute discovery call

    A direct conversation with Adam to confirm the scope, platform, start date, rate, and working arrangement. No intermediary. No recruiter listening in. You speak to the engineer from minute one.

    Typically within 24–48 hours of initial contact

  3. 3

    Statement of work & contract

    iCoreFusion issues a clean B2B contract — UK Ltd for UK and European clients, US LLC for US, Canadian, and Australian clients. Standard vendor onboarding documentation provided on request including W-9 for US engagements.

    Contract issued within 24 hours of agreement

  4. 4

    Start date confirmed — immediate availability

    Adam is available to start immediately or on a date that suits your project timeline. Remote onboarding takes one business day. For onsite UK engagements, travel can be arranged within 48 hours of contract signature.

    Immediate start available · June 2026

Common questions

FAQs from hiring managers

Can you work outside IR35?

Yes. iCoreFusion Ltd is a UK limited company and Adam operates as a genuine B2B contractor. For roles assessed as outside IR35, engagements are structured directly with iCoreFusion Ltd. For roles inside IR35, umbrella arrangements can be discussed.

Can you work Corp-to-Corp for US engagements?

Yes. iCoreFusion LLC is a registered USA entity. US clients can engage directly Corp-to-Corp without needing an agency or employer of record. Standard W-9 and vendor documentation provided on request.

What is your notice period or availability?

Immediate start available as of June 2026. For ongoing contracts, standard notice period is two weeks unless otherwise agreed in the statement of work.

Do you work with agencies or only direct?

Both — but direct is preferred and always cheaper for you. iCoreFusion works directly with clients wherever possible. If your procurement process requires an agency, Adam can be engaged through a preferred supplier.

What platforms have you worked on most recently?

Elastic Security at BT (Jan–Mar 2026) and Microsoft Sentinel at Charles River Associates (May 2024–Dec 2025). Both at senior engineering level. QRadar and Splunk from earlier enterprise roles at IBM and Ford Motor Company.

Can a contract lead to a permanent hire?

Yes — and we actively support this. iCoreFusion offers a formal contract-to-hire pathway. After a minimum 6-month engagement, if both parties want to transition to a permanent arrangement, iCoreFusion supports the handover. A conversion fee applies.

What languages do you work in?

English and French — both fluent. Adam has delivered engagements across the UK, Switzerland, and USA and is comfortable working in international team environments.

Ready to Start the Conversation?

No agency. No forms. No waiting room. Send a direct message and Adam responds personally — usually within a few hours.