SIEM Engineer – Senior – EY GDS Spain – Hybrid
As a Senior SIEM Engineer, you are part of the EY Cyber Security team, working in a Threat Detection & Response (TDR) environment with a strong focus on Microsoft Sentinel and XDR. You design, integrate, and operate SIEM use cases and automations and support clients in securely operating modern cloud-native security platforms. Knowledge of Splunk or open-source SIEM ecosystems (e.g., Elastic/ELK, Wazuh) is considered a strong advantage.
Your Key Responsibilities
Integrate data sources into Microsoft Sentinel (cloud, identity, endpoint, network, and on-prem) and ensure data quality and normalization.
Design, implement, and operate analytics rules, SIEM use cases, and hunting queries (KQL; SPL experience is a plus).
Develop and maintain playbooks and automations using Azure Logic Apps to enrich, orchestrate, and standardize response workflows.
Act as a technical subject matter expert for SIEM and Microsoft Sentinel/XDR solutions and provide hands‑on guidance to stakeholders.
Optimize SOC Operations
Continuously optimize detection,
response, and automation capabilities (tuning, false‑positive reduction, performance, and maintainability).
Contribute to engineering best practices such as documentation, repeatable deployments, and (where applicable) detection/content as code.
Skills and Attributes for Success
Strong knowledge of cloud security concepts, SIEM architectures, and the MITRE ATT&CK; framework.
Hands‑on engineering mindset with solid troubleshooting, analytical thinking, and attention to detail.
Pragmatic communicator who can translate complex technical topics into actionable recommendations for different audiences.
Ownership and quality focus: audit‑ready documentation, structured delivery, and continuous improvement.
To Qualify for the Role
2 – + 4 years of experience in SIEM engineering (design, onboarding, use case development, tuning, and operations), ideally with Microsoft Sentinel.
Hands‑on ex
📌 Senior SIEM Engineer (Madrid)
🏢 Ey
📍 Madrid