ph3SIEM Engineer – Senior – EY GDS Spain – Hybrid /h3 pAs a Senior SIEM Engineer, you are part of the EY Cyber Security team, working in a Threat Detection Response (TDR) environment with a strong focus on Microsoft Sentinel and XDR. You design, integrate, and operate SIEM use cases and automations and support clients in securely operating modern cloud-native security platforms. Knowledge of Splunk or open-source SIEM ecosystems (e.g., Elastic/ELK, Wazuh) is considered a strong advantage. /p h3Your Key Responsibilities /h3 ul liIntegrate data sources into Microsoft Sentinel (cloud, identity, endpoint, network, and on-prem) and ensure data quality and normalization. /li liDesign, implement, and operate analytics rules, SIEM use cases, and hunting queries (KQL; SPL experience is a plus). /li liDevelop and maintain playbooks and automations using Azure Logic Apps to enrich, orchestrate, and standardize response workflows. /li liAct as a technical subject matter expert for SIEM and Microsoft Sentinel/XDR solutions and provide hands‑on guidance to stakeholders. /li /ul h3Optimize SOC Operations /h3 ul liContinuously optimize detection, response, and automation capabilities (tuning, false‑positive reduction, performance, and maintainability). /li liContribute to engineering best practices such as documentation, repeatable deployments, and (where applicable) detection/content as code.
/li /ul h3Skills and Attributes for Success /h3 ul liStrong knowledge of cloud security concepts, SIEM architectures, and the MITRE ATTCK framework. /li liHands‑on engineering mindset with solid troubleshooting, analytical thinking, and attention to detail. /li liPragmatic communicator who can translate complex technical topics into actionable recommendations for different audiences. /li liOwnership and quality focus: audit‑ready documentation, structured delivery, and continuous improvement. /li /ul h3To Qualify for the Role /h3 ul li2 – + 4 years of experience in SIEM engineering (design, onboarding, use case development, tuning, and operations), ideally with Microsoft Sentinel. /li liHands‑on experience with Azure, Windows/Linux, and scripting (e.g., Python, PowerShell, Bash) as well as automation concepts. /li liExperience building or operating SOAR‑style automations (e.g., Logic Apps / playbooks) in a security operations context. /li liEnglish at least B2 (written and spoken) is required. /li /ul h3Ideally you'd also have /h3 ul liSplunk experience (SPL, data onboarding, correlations, dashboards) and/or open-source SIEM experience (e.g., Elastic/ELK, Wazuh). /li liExperience working in regulated environments and familiarity with operational processes (ITSM, incident workflow alignment). /li liRelevant certifications (e.g., SC-200, AZ‑500, or comparable cloud/security certifications) are a plus. /li /ul /p #J-18808-Ljbffr
📌 Senior SIEM Engineer - EY GDS Spain - Hybrid (Málaga)
🏢 Ey
📍 Málaga