SIEM Security Engineer

EY

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Learning opportunities
Certification sponsorship
Flexible working arrangements

Job summary

EY invites applications for a SIEM Engineer (Senior Analyst) in India to support the Microsoft Sentinel-based SIEM platform across cloud and on‑prem environments. You will engage with cross‑functional teams to implement, tune, and operate security monitoring at scale.

The role emphasizes hands‑on engineering, collaboration with SOC and cloud teams, and a focus on automation and documentation to strengthen EY's security posture.

Qualifications

  • 3–5 years of experience in IT security or related technical field with growing exposure to SIEM engineering.
  • Hands-on experience with Microsoft Sentinel or a comparable SIEM platform.
  • Basic proficiency with KQL or similar query languages for log investigation and rule creation.
  • Foundational knowledge of cloud environments: Azure (primary), with awareness of AWS and/or GCP.
  • Basic scripting skills in Python, PowerShell, or Bash for task automation.
  • Understanding of security event sources: Windows Event Logs, Syslog, firewalls, and endpoint agents.

Responsibilities

  • Support the deployment, configuration, and management of SIEM solutions across On-Premises, Hybrid, and Cloud Based environments following EY standards.
  • Assist in the deployment and management of Azure Monitor Agent (AMA) and Azure ARC for connected machines.
  • Support data pipeline operations: onboarding new log sources using out-of-the-box connectors, Syslog/CEF ingestion, and stream processing tools.
  • Assist in building and maintaining Logic Apps and Azure Functions for automated response workflows.
  • Support Azure RBAC management as it applies to Microsoft Sentinel and Log Analytics Workspaces.
  • Assist with data transformation and optimization - normalization, parsing of raw logs, and basic tuning of ingestion volumes and retention policies.
  • Support external cloud vendor log ingestion pipelines (AWS, GCP, Zscaler, etc.) under senior engineer guidance.
  • Serve as a technical escalation point for SOC analysts on SIEM-related queries and investigations.
  • Contribute to technical documentation: runbooks, configuration guides, and engineering standards.
  • Develop professional skills through collaboration with senior engineers and architects.

Skills

SIEM engineering
Cloud security basics
English communication

Education

Bachelor's degree in computer science, engineering, IT, mathematics

Tools

Microsoft Sentinel
Azure Monitor
Azure Arc
KQL
PowerShell
Python
Syslog/CEF
Logic Apps
AWS
GCP

Job description

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Security Monitoring – SIEM Engineer
The Opportunity

Today's world is fueled by vast amounts of information, making data more valuable - and more vulnerable - than ever. As a SIEM Engineer at the Senior Analyst level within our Global Delivery Services (GDS) center in India, you will become a key contributor to the Security Technology Services (STS) group. You will support the engineering lifecycle - deployment, configuration, integration, and ongoing maintenance - of our Microsoft Sentinel-based SIEM platform and related security monitoring technologies across cloud and on-premises environments. This is a hands-on engineering role where you will grow your technical capabilities while contributing to how EY detects and responds to threats at enterprise scale. You will collaborate with Security Architects, Cloud Engineers, Security Operations, and SOC Analysts across time zones, supporting SIEM and security monitoring services under the guidance of senior engineers.

Your Key Responsibilities
  • Support the deployment, configuration, and management of SIEM solutions across On-Premises, Hybrid, and Cloud Based environments following EY standards.
  • Assist in the deployment and management of Azure Monitor Agent (AMA) and Azure ARC for connected machines.
  • Support data pipeline operations: onboarding new log sources using out-of-the-box connectors, Syslog/CEF ingestion, and stream processing tools.
  • Assist in building and maintaining Logic Apps and Azure Functions for automated response workflows.
  • Support Azure RBAC management as it applies to Microsoft Sentinel and Log Analytics Workspaces.
  • Assist with data transformation and optimization - normalization, parsing of raw logs, and basic tuning of ingestion volumes and retention policies.
  • Support external cloud vendor log ingestion pipelines (AWS, GCP, Zscaler, etc.) under senior engineer guidance.
  • Serve as a technical escalation point for SOC analysts on SIEM-related queries and investigations.
  • Contribute to technical documentation: runbooks, configuration guides, and engineering standards.
  • Develop professional skills through collaboration with senior engineers and architects.
Skills And Attributes For Success
  • Good understanding of SIEM platforms and their role within enterprise security operations.
  • Foundational knowledge of Microsoft Sentinel: data connectors, Analytic Rules, Workbooks, and Watchlists.
  • Familiarity with data pipeline concepts: log normalization, CEF/Syslog, and log ingestion strategies.
  • Basic awareness of SOAR concepts (Logic Apps or equivalent) and automation workflows.
  • Understanding of compliance and vulnerability management frameworks and how they relate to security monitoring.
  • Effective communicator in English (written and verbal) — able to convey technical concepts clearly.
  • Eager to learn and improve; continuous-improvement mindset with an interest in automation.
To Qualify for the Role, You Must Have
  • 3–5 years of experience in IT Security or a related technical field, with growing exposure to SIEM engineering.
  • Hands-on experience with Microsoft Sentinel or a comparable SIEM platform
  • Basic proficiency with KQL or similar query languages for log investigation and rule creation.
  • Foundational knowledge of cloud environments: Azure (primary), with awareness of AWS and/or GCP.
  • Basic scripting skills in Python, PowerShell, or Bash for task automation.
  • Understanding of security event sources: Windows Event Logs, Syslog, firewalls, and endpoint agents.
Ideally, You Will Also Have
  • Bachelor’s degree in computer science, Engineering, IT, Mathematics, or equivalent work experience.
  • Cloud or security certification: Microsoft SC-200 / AZ-500, CompTIA Security+, Splunk Core Certified User, or equivalent.
  • Exposure to SOAR platforms (Logic Apps, Cortex XSOAR, or equivalent).
  • Familiarity with the MITRE ATT&CK framework and its use in detection engineering.
  • Experience working in a SOC or security monitoring environment.
What We Look For

This role is ideal for a developing security engineer who is building their SIEM expertise within a compliance and security monitoring environment. We are looking for people who:

  • Are eager to solve technical problems in a large enterprise-scale environment.
  • Can translate security requirements into working configurations and rules under guidance.
  • Work collaboratively across a globally distributed team.
  • Bring attention to detail: structured documentation, consistent configurations, and clear communication.
What We Offer
  • Continuous learning: Access to EY's global learning platforms, technical training, and certification sponsorship.
  • Success as defined by you: Tools and flexibility to make a significant impact — deepen your technical specialization or grow into architecture or leadership.
  • Transformative leadership: Coaching and confidence-building to help you grow as a technical leader globally.
  • Diverse and inclusive culture: You will be accepted for who you are; flexible working arrangements supported.
  • Competitive compensation aligned to the India technology market, including performance-based incentives.

EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GMS-Senior- SecOps-Sentinel
GMS-Senior- SecOps-Sentinel

EY • Chennai District

On-site
INR 1,200,000 - 2,400,000
GMS-Senior- SecOps-Sentinel
GMS-Senior- SecOps-Sentinel

Ernst & Young Advisory Services Sdn Bhd • Chennai District

On-site
INR 1,400,000 - 2,200,000
Senior Cybersecurity Engineer - Sentinel SOAR
Senior Cybersecurity Engineer - Sentinel SOAR

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 1,800,000 - 3,200,000
CMS-Senior-Sentinel SOAR
CMS-Senior-Sentinel SOAR

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 1,200,000 - 2,100,000
CMS-Senior-Sentinel
CMS-Senior-Sentinel

Ernst & Young Advisory Services Sdn Bhd • Thiruvananthapuram

On-site
INR 800,000 - 1,200,000
Support and feedback from engaging colleagues
Opportunities to develop new skills
Freedom and flexibility in managing the role
GMS-Manager-SecOps-Sentinel
GMS-Manager-SecOps-Sentinel

EY • Bengaluru Urban

On-site
INR 3,000,000 - 6,000,000
GMS-Manager-SecOps-Sentinel
GMS-Manager-SecOps-Sentinel

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 2,500,000 - 4,500,000
GMS-Manager-SecOps-Sentinel
GMS-Manager-SecOps-Sentinel

EY • Thiruvananthapuram

On-site
INR 1,800,000 - 2,400,000
Security Engineer - Cloud & Third Party Security Tooling Specialist
Security Engineer - Cloud & Third Party Security Tooling Specialist

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Continuous learning
Certification sponsorship
Flexible working arrangements
+1
EY - Cybersecurity - SOC- Incident Response and Threat Intelligence - Manager
EY - Cybersecurity - SOC- Incident Response and Threat Intelligence - Manager

EY • Ernakulam

On-site
INR 3,000,000 - 6,000,000