{"id":1275537,"url":"https://alion.io/job/ernst-young-siem-security-engineer","title":"SIEM Security Engineer","company":{"id":2859,"name":"Ernst & Young","domain":"ey.com","url":"https://alion.io/company/ey-com","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":16000,"max_usd":40000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":414},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Cortex","optional":false},{"name":"Cortex XSOAR","optional":false},{"name":"GCP","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"Windows","optional":false},{"name":"Zscaler","optional":false},{"name":"Prometheus","optional":true}],"status":"live","first_seen_at":"2026-09-22T00:00:00Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-10-01T18:37:34Z","board_verified":true,"closed_at":null,"days_open":9,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":9},"description":"At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.\nSecurity Monitoring - SIEM Engineer\nThe Opportunity\nToday's world is fueled by vast amounts of information, making data more valuable - and more vulnerable - than ever. As a SIEM Engineer at the Senior Analyst level within our Global Delivery Services (GDS) center in India, you will become a key contributor to the Security Technology Services (STS) group. You will support the engineering lifecycle - deployment, configuration, integration, and ongoing maintenance - of our Microsoft Sentinel-based SIEM platform and related security monitoring technologies across cloud and on-premises environments. This is a hands-on engineering role where you will grow your technical capabilities while contributing to how EY detects and responds to threats at enterprise scale. You will collaborate with Security Architects, Cloud Engineers, Security Operations, and SOC Analysts across time zones, supporting SIEM and security monitoring services under the guidance of senior engineers.\nYour Key Responsibilities\nSupport the deployment, configuration, and management of SIEM solutions across On-Premises, Hybrid, and Cloud Based environments following EY standards.\nAssist in the deployment and management of Azure Monitor Agent (AMA) and Azure ARC for connected machines.\nSupport data pipeline operations: onboarding new log sources using out-of-the-box connectors, Syslog/CEF ingestion, and stream processing tools.\nAssist in building and maintaining Logic Apps and Azure Functions for automated response workflows.\nSupport Azure RBAC management as it applies to Microsoft Sentinel and Log Analytics Workspaces.\nAssist with data transformation and optimization - normalization, parsing of raw logs, and basic tuning of ingestion volumes and retention policies.\nSupport external cloud vendor log ingestion pipelines (AWS, GCP, Zscaler, etc.) under senior engineer guidance.\nServe as a technical escalation point for SOC analysts on SIEM-related queries and investigations.\nContribute to technical documentation: runbooks, configuration guides, and engineering standards.\nDevelop professional skills through collaboration with senior engineers and architects.\nSkills and Attributes for Success\nGood understanding of SIEM platforms and their role within enterprise security operations.\nFoundational knowledge of Microsoft Sentinel: data connectors, Analytic Rules, Workbooks, and Watchlists.\nFamiliarity with data pipeline concepts: log normalization, CEF/Syslog, and log ingestion strategies.\nBasic awareness of SOAR concepts (Logic Apps or equivalent) and automation workflows.\nUnderstanding of compliance and vulnerability management frameworks and how they relate to security monitoring.\nEffective communicator in English (written and verbal) - able to convey technical concepts clearly.\nEager to learn and improve; continuous-improvement mindset with an interest in automation.\nTo Qualify for the Role, You Must Have\n3-5 years of experience in IT Security or a related technical field, with growing exposure to SIEM engineering.\nHands-on experience with Microsoft Sentinel or a comparable SIEM platform\nBasic proficiency with KQL or similar query languages for log investigation and rule creation.\nFoundational knowledge of cloud environments: Azure (primary), with awareness of AWS and/or GCP.\nBasic scripting skills in Python, PowerShell, or Bash for task automation.\nUnderstanding of security event sources: Windows Event Logs, Syslog, firewalls, and endpoint agents.\nIdeally, You Will Also Have\nBachelor’s degree in computer science, Engineering, IT, Mathematics, or equivalent work experience.\nCloud or security certification: Microsoft SC-200 / AZ-500, CompTIA Security+, Splunk Core Certified User, or equivalent.\nExposure to SOAR platforms (Logic Apps, Cortex XSOAR, or equivalent).\nFamiliarity with the MITRE ATT&CK framework and its use in detection engineering.\nExperience working in a SOC or security monitoring environment.\nWhat We Look For\nThis role is ideal for a developing security engineer who is building their SIEM expertise within a compliance and security monitoring environment. We are looking for people who:\nAre eager to solve technical problems in a large enterprise-scale environment.\nCan translate security requirements into working configurations and rules under guidance.\nWork collaboratively across a globally distributed team.\nBring attention to detail: structured documentation, consistent configurations, and clear communication.\nWhat We Offer\nContinuous learning: Access to EY's global learning platforms, technical training, and certification sponsorship.\nSuccess as defined by you: Tools and flexibility to make a significant impact - deepen your technical specialization or grow into architecture or leadership.\nTransformative leadershi p: Coaching and confidence-building to help you grow as a technical leader globally.\nDiverse and inclusive culture: You will be accepted for who you are; flexible working arrangements supported.\nCompetitive compensation aligned to the India technology market, including performance-based incentives.\nEY | Building a better working world\nEY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.\nEnabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.\nWorking across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.","description_format":"text","description_chars":5933,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[{"language":"English","level":"Upper-Intermediate (B2)","optional":false}]},"benefits":["Continuous learning","Flexible schedule"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Security Operations","Financial Advisory, Valuation & Restructuring","Management Consulting","Tax Advisory & Preparation"],"lifecycle":[{"event":"open","at":"2026-09-26T01:25:14Z"}],"liveness":{"score":75,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.833,"p_room":0.9,"age_days":9,"expected_fill_days":18,"reasons":["conf:7","velocity","win:mid","comp:brand"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/ernst-young-siem-security-engineer","json_url":"https://alion.io/job/ernst-young-siem-security-engineer.json","meta":{"generated_at":"2026-10-01T19:36:02Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2248,"day_limit":5000,"remaining_today":2752,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}