Ernst & Young LLP ( EY India )

Senior SIEM Engineer

Ernst & Young LLP ( EY India )
Thiruvananthapuram
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 3 yearsMin. 3 years

Job Description

TC-CS-CDR-NG SIEM-Senior

At EY, we’re all in to shape your future with confidence. 

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. 

Join EY and help to build a better working world. 

 

NGSIEM JD details for Senior

 

Senior

Role Summary

The NG SIEM Senior role leads ingestion engineering, detection creation, and integrated case management and correlation workflows. This role partners with threat, cloud, and IR teams to enhance automation, reduce noise, and strengthen the SIEM–SOAR ecosystem.

 

Key Responsibilities

  • Lead onboarding of strategic log sources via Cribl, cloud collectors, API pipelines.
  • Build and optimize parsing, normalization, and enrichment logic.
  • Create advanced detections mapped to MITRE ATT&CK using SPL/KQL/CQL/CQL-Advanced.
  • Design and optimize correlation logic using Fusion/ML-based engines.
  • Lead tuning and noise-reduction activities for Fusion correlation rules.
  • Oversee case lifecycle management: triage workflows, enrichments, severity logic, and SLA tracking.
  • Develop and maintain SOAR playbooks for automated enrichment, notifications, containment tasks.
  • Integrate external systems (EDR, IAM, Email, Firewall) into SOAR workflows.
  • Conduct root-cause analysis for ingestion and correlation gaps.
  • Collaborate with Threat Intel and Detection teams for new use cases.
  • Leverage AI assistants like Charlotte AI and Sentinel Copilot to optimize detection creation, accelerate query building, and reduce investigation time.
  • Integrate Microsoft Sentinel with Copilot to enable AI-driven incident summarization, RCA assistance, KQL generation, and automated SOC workflows.
  • Evaluate and implement AI‑powered SOAR capabilities, including automated enrichment, clustering of similar alerts, and anomaly‑based playbook triggers.

 

Skills & Experience

  • 3–6 years in SIEM engineering or SOC detection.
  • Strong hands-on experience with Fusion Correlation Engine (CrowdStrike), Azure Sentinel Analytics, or Splunk ES Correlation Searches.
  • Experience creating/maintaining SOAR playbooks (Fusion workflows, Sentinel Logic Apps, Splunk SOAR).
  • Deep knowledge of case management workflows and alert lifecycle governance.
  • Strong in ingestion engineering using Cribl Stream & Lake.
  • Expertise in SPL, KQL, CQL query languages.
  • Understanding of data models, schemas, threat modelling.

 

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

Experience Level

Senior Level

Job role

Work location
Work locationTrivandrum, KL, IN, 695581
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 3 years

About company

Name
NameErnst & Young LLP ( EY India )
Job posted by Ernst & Young LLP ( EY India )

Similar jobs you can apply for

IT Security
Ernst & Young LLP ( EY India )

Senior Technical Engineer

Ernst & Young LLP ( EY India )
Thiruvananthapuram
Work from Office
Full Time
Min. 2 years
Ernst & Young LLP ( EY India )

Network Security Engineer

Ernst & Young LLP ( EY India )
Thiruvananthapuram
Work from Office
Full Time
Any experience
Ernst & Young LLP ( EY India )

Network Security Engineer

Ernst & Young LLP ( EY India )
Thiruvananthapuram
Work from Office
Full Time
Min. 2 years
Ernst & Young LLP ( EY India )

Network Security Engineer

Ernst & Young LLP ( EY India )
Thiruvananthapuram
Work from Office
Full Time
Min. 4 years
Ernst & Young LLP ( EY India )

Network Security Engineer

Ernst & Young LLP ( EY India )
Thiruvananthapuram
Work from Office
Full Time
Min. 3 years
Equifax Credit Information Services Pvt Ltd

Engineering Manager

Equifax Credit Information Services Pvt Ltd
Thiruvananthapuram
Work from Office
Full Time
Min. 8 years