Security Engineer

EY

Bengaluru

On-site

INR 4,000,000 - 6,000,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Continuous learning
Certification sponsorship
Coaching and leadership development
Diverse and inclusive culture
Competitive compensation

Job summary

EY's STS Lab in Bengaluru seeks a Monitoring & AI Protection Engineer to own 3rd party security tooling across multi‑cloud environments. You will implement, configure, and integrate Zscaler, Qualys, Wiz, and CSPM tooling with EY's security stack, ensuring cohesive governance and visibility.

You will build automation in Python/PowerShell, develop KQL detection rules, and collaborate with IAM and SIEM teams globally to translate tooling capabilities into strengthened security outcomes.

Qualifications

  • 5+ years of experience in Security Engineering, Cloud Security, or a related technical discipline.
  • Hands-on ownership of 3rd party security tooling in enterprise environments.
  • Experience integrating security platforms with SIEM/SOAR or cloud-native stacks.

Responsibilities

  • Own end-to-end engineering, configuration, and lifecycle management of 3rd party security platforms.
  • Design integrations between 3rd party tools and EY's security stack (Defender XDR, Sentinel, Event Hubs).
  • Engineer and maintain CSPM capabilities and remediation workflows across Azure, AWS, and GCP.
  • Configure scanning, asset inventory, and reporting pipelines for vulnerabilities.
  • Build and maintain log ingestion pipelines into Microsoft Sentinel and Log Analytics.
  • Develop Python/PowerShell automation scripts and GitHub Actions workflows.
  • Maintain STS Lab environments for PoC and testing of new tooling.
  • Produce and maintain engineering runbooks and documentation.

Skills

Security engineering
Cloud security
Automation (Python/PowerShell)
SIEM/KQL

Education

Bachelor's degree in Computer Science or related field

Tools

Zscaler
Qualys
Wiz
CSPM tools
Microsoft Sentinel

Job description

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

STS Lab Security Engineer
The Opportunity

The EY Security Technology Services (STS) Lab is the innovation and engineering engine behind EY's global cybersecurity platform — responsible for building, testing, integrating, and continuously improving the security tooling that protects one of the world's largest professional services organizations. As a Monitoring & AI Protection Engineer at the Assistant Director level within the STS Lab team in GDS India, you will be the hands‑on technical owner of EY's 3rd party security tooling ecosystem — spanning Zscaler, Qualys, Wiz, CSPM platforms, and their integrations into EY's broader security architecture. You will own the engineering, configuration, integration, and continuous improvement of these platforms, ensuring they operate as cohesive, well‑governed components of EY's Monitoring & AI Protection capability. This is a hands‑on, senior engineering role with direct influence over how EY's security posture is monitored, assessed, and protected across multi‑cloud environments. You will work closely with the STS Lab Lead, Cloud Platform Security Architects, and SMEs across IAM, Defender XDR, Sentinel, and the broader Monitoring & AI Protection team to translate platform capabilities into actionable security outcomes at enterprise scale.

Your Key Responsibilities
  • 3rd Party Platform Engineering — Own end‑to‑end engineering, configuration, and lifecycle management of Zscaler (ZIA/ZPA/ZDX), Qualys (VMDR/WAS/CS), Wiz, and CSPM tooling across multi‑cloud environments.
  • Integration Architecture — Design and implement integrations between 3rd party tools and EY's core security stack (Microsoft Sentinel, Defender XDR, Event Hubs, REST APIs), ensuring unified visibility and alerting across the security platform.
  • Engineer and maintain Cloud Security Posture Management capabilities; define and enforce policy frameworks, benchmark mappings (CIS, NIST, PCI‑DSS), and remediation workflows across Azure, AWS, and GCP.
  • Vulnerability & Exposure Management — Configure and manage scanning infrastructure, asset inventory, and reporting pipelines; integrate vulnerability findings into downstream risk and remediation workflows.
  • Monitoring & Alerting Pipelines — Build and maintain log ingestion pipelines from 3rd party tools into Microsoft Sentinel and Log Analytics Workspaces; develop KQL‑based detection rules, dashboards, and workbooks.
  • Automation & Tooling — Develop Python/PowerShell automation scripts and GitHub Actions workflows to streamline platform operations, policy deployment, and integration tasks.
  • Lab Environment Testing — Build and maintain STS Lab environments to evaluate new 3rd party tooling capabilities, proof‑of‑concept integrations, and product updates prior to production deployment.
  • Documentation & Runbooks — Produce and maintain clear engineering documentation, integration runbooks, configuration standards, and operational guides for global distribution.
Skills And Attributes For Success
  • Deep, hands‑on experience engineering and administering 3rd party security platforms in large enterprise, multi‑cloud environments.
  • Strong command of at least two of the following: Zscaler (ZIA/ZPA), Qualys (VMDR/WAS), Wiz, or equivalent CSPM tooling — with demonstrable integration experience.
  • Solid understanding of CSPM principles: cloud misconfiguration detection, compliance benchmarking, and posture remediation workflows.
  • Familiarity with SIEM integration patterns: log connectors, API‑based ingestion, Event Hub pipelines, and KQL for detection and investigation.
  • Understanding of Zero Trust architecture principles and how proxy, CASB, and identity‑aware access controls are implemented in practice.
  • Effective communicator in English (written and verbal) — able to convey complex technical concepts to both technical and non‑technical stakeholders across globally distributed teams.
  • Hands‑on automation mindset — Python and/or PowerShell for operational scripting, API integrations, and configuration management.
To Qualify for the Role, You Must Have
  • 5+ years of experience in Security Engineering, Cloud Security, or a related technical discipline with demonstrable hands‑on ownership of 3rd party security tooling.
  • 3+ years of direct, hands‑on experience with at least two of: Zscaler, Qualys, Wiz, or CSPM platforms in an enterprise environment.
  • Proven ability to design and implement integrations between 3rd party security platforms and SIEM/SOAR or cloud‑native security stacks.
  • Technical proficiency with Microsoft Azure: subscriptions, RBAC, Log Analytics Workspaces, Event Hubs, and Microsoft Sentinel.
  • Scripting proficiency: Python and/or PowerShell for automation, API integrations, and platform configuration tasks.
  • Working knowledge of multi‑cloud environments: Azure (primary), with hands‑on or working knowledge of AWS and/or GCP from a security posture perspective.
Ideally, You Will Also Have
  • Bachelor’s degree in computer science, Engineering, IT, or a related field — or equivalent work experience.
  • Microsoft certification: AZ‑104, AZ‑204, AZ‑500, SC‑200, SC‑100.
  • Security certification: CISSP, CCSP, GSEC, GCLD, or equivalent (ISC2 / GIAC).
  • Zscaler / Qualys / Wiz certification
  • Experience with CI/CD pipelines (GitHub Actions or Azure DevOps) for version‑controlled configuration and policy deployment.
  • Familiarity with MITRE ATT&CK and how 3rd party tooling coverage maps to adversary techniques.
What We Look For

This role is ideal for a seasoned security engineer who combines deep 3rd party tooling expertise with an integration and automation mindset. We are looking for people who:

  • Take end‑to‑end ownership of platforms: from initial configuration through to production‑quality integrations and ongoing engineering health.
  • Translate security architecture requirements into working, documented platform configurations and data pipelines.
  • Drive outcomes independently while remaining collaborative across a globally distributed team spanning multiple time zones.
  • Bring engineering discipline: reproducible configurations, version‑controlled deployments, and documentation others can execute without hand‑holding.
  • Operate with a startup mindset inside a large global organization — proactive, adaptable, and solutions‑oriented.
What We Offer
  • Continuous learning: Access to EY's global learning platforms, technical training, and certification sponsorship.
  • Success as defined by you: Tools and flexibility to make a significant impact — deepen your technical specialization or grow into cloud engineering or architecture roles.
  • Transformative leadership: Coaching and confidence‑building to help you grow as a technical leader globally.
  • Diverse and inclusive culture: You will be accepted for who you are; flexible working arrangements supported.
  • Competitive compensation aligned to the Argentine senior technology market, including performance‑based incentives.
EY | Building a better working world

EY exists to build a better working world, helping to create long‑term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer - Cloud & Third Party Security Tooling Specialist
Security Engineer - Cloud & Third Party Security Tooling Specialist

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Continuous learning
Certification sponsorship
Flexible working arrangements
+1
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior
TC-CS-Cyber Architecture-OT and Engineering-ZScaler-Senior

EY • Dadri

On-site
INR 1,500,000 - 2,300,000
Senior Zscaler Security Consultant
Senior Zscaler Security Consultant

EY • Dadri

On-site
INR 4,000,000 - 7,000,000
TC-CS-Cyber Architecture-OT and Engineering-Zscaler SASE-Senior
TC-CS-Cyber Architecture-OT and Engineering-Zscaler SASE-Senior

EY • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Zscaler Network Security-Principal Engineer- Associate Director
Zscaler Network Security-Principal Engineer- Associate Director

EY • Bengaluru Urban

On-site
INR 6,000,000 - 9,000,000
Zscaler Network Security-Principal engineer- Associate director
Zscaler Network Security-Principal engineer- Associate director

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 4,200,000 - 7,000,000
Zscaler Network Security-Principal engineer- Associate director
Zscaler Network Security-Principal engineer- Associate director

EY • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Flexible working arrangements
Total rewards package
Career development opportunities
+1
Security Technology - Data Protection Technology Operations Technician
Security Technology - Data Protection Technology Operations Technician

EY • Bengaluru

On-site
INR 900,000 - 1,300,000
Continuous learning
Diverse and inclusive culture
Zscaler Network Security Engineer
Zscaler Network Security Engineer

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 3,000,000 - 5,400,000
Zscaler Network Security Engineer
Zscaler Network Security Engineer

EY • Bengaluru Urban

Hybrid
INR 1,400,000 - 2,100,000