Ernst and Young

TC - CS - CDR - SIEM Content Developer - Senior

Ernst and Young
Apply
16 hours ago
Bengaluru, IndiaSenior

Responsibilities

  • Design and develop SIEM use cases tailored to OT environments.
  • Onboard, parse, mask, validate, and process data from supported and unsupported log sources.
  • Develop and tune SIEM rules, alerts, reports, correlation logic, incident classifications, and prioritization recommendations.
  • Create advanced dashboards and visualizations for near real-time visibility into OT applications.
  • Support planning, installation, configuration, testing, troubleshooting, reporting, and problem resolution for SIEM and OT monitoring systems.
  • Provide operational support for globally deployed Nozomi, Claroty, and Armis solutions.
  • Guide clients in configuring log sources, optimizing SIEM capabilities, and implementing audit and logging features.
  • Design and document SIEM solutions and automated security event monitoring and response processes.
  • Create use cases aligned with the Cyber Kill Chain and MITRE ATT&CK framework.
  • Provide consulting and technical guidance throughout testing, evaluation, pilot, production, and training phases.

Requirements

  • At least 8 years of overall cybersecurity experience, including at least 4 years in OT/IoT security solutions.
  • Strong knowledge of IT, OT, and IoT communication and industrial protocols.
  • Strong background in network administration and the ability to work across all OSI model layers.
  • Knowledge of vulnerability management, Windows and Linux administration, Windows domains, trusts, GPOs, server roles, security policies, user administration, Linux security, and troubleshooting.
  • Programming or scripting experience with Python, JavaScript, Bash, or PowerShell.
  • Experience designing and implementing Splunk for IT Operations, Application Analytics, User Experience, Application Performance, and Security Management is preferred.
  • Experience with multiple Splunk cluster deployments and management according to vendor guidelines and industry best practices is preferred.
  • Ability to troubleshoot Splunk platform and application issues and coordinate resolution with Splunk Support is preferred.
  • Certification in Splunk, IBM QRadar, Exabeam, Securonix, or another SIEM solution is advantageous.
  • Certifications in a core security discipline are advantageous.
  • Strong oral, written, listening, consulting, and client-facing communication skills.

Tech Stack

BashJavaScriptLinuxPowerShellPythonSplunkWindows

Categories

SecuritySolutions Engineering
Ernst and Young

About Ernst and Young

10,000+ employees

Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.

Contact me