
TC - CS - CDR - SIEM Content Developer - Senior
Ernst and Young16 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Design and develop SIEM use cases tailored to OT environments.
- Onboard, parse, mask, validate, and process data from supported and unsupported log sources.
- Develop and tune SIEM rules, alerts, reports, correlation logic, incident classifications, and prioritization recommendations.
- Create advanced dashboards and visualizations for near real-time visibility into OT applications.
- Support planning, installation, configuration, testing, troubleshooting, reporting, and problem resolution for SIEM and OT monitoring systems.
- Provide operational support for globally deployed Nozomi, Claroty, and Armis solutions.
- Guide clients in configuring log sources, optimizing SIEM capabilities, and implementing audit and logging features.
- Design and document SIEM solutions and automated security event monitoring and response processes.
- Create use cases aligned with the Cyber Kill Chain and MITRE ATT&CK framework.
- Provide consulting and technical guidance throughout testing, evaluation, pilot, production, and training phases.
Requirements
- At least 8 years of overall cybersecurity experience, including at least 4 years in OT/IoT security solutions.
- Strong knowledge of IT, OT, and IoT communication and industrial protocols.
- Strong background in network administration and the ability to work across all OSI model layers.
- Knowledge of vulnerability management, Windows and Linux administration, Windows domains, trusts, GPOs, server roles, security policies, user administration, Linux security, and troubleshooting.
- Programming or scripting experience with Python, JavaScript, Bash, or PowerShell.
- Experience designing and implementing Splunk for IT Operations, Application Analytics, User Experience, Application Performance, and Security Management is preferred.
- Experience with multiple Splunk cluster deployments and management according to vendor guidelines and industry best practices is preferred.
- Ability to troubleshoot Splunk platform and application issues and coordinate resolution with Splunk Support is preferred.
- Certification in Splunk, IBM QRadar, Exabeam, Securonix, or another SIEM solution is advantageous.
- Certifications in a core security discipline are advantageous.
- Strong oral, written, listening, consulting, and client-facing communication skills.
Tech Stack
Categories
SecuritySolutions Engineering
About Ernst and Young
Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.