TC - CS - CDR - SIEM Content Developer - Senior

EY

8+ yrs Bengaluru Full Time Hybrid (office + remote)
EY logo
Posted : 4 days ago
Actively hiring

Job description

EY is seeking a highly skilled Senior SIEM Specialist with significant Operational Technology (OT) expertise to join our cybersecurity team. This role is pivotal in designing and implementing advanced threat detection and response capabilities within OT environments. You will leverage your deep understanding of SIEM content development and OT tools to enhance our clients' security posture and build a better working world.

As a Senior SIEM Specialist, you will play a critical role in safeguarding operational technology systems. Your contributions will directly impact the security and reliability of industrial environments, ensuring robust protection against evolving cyber threats. Join a global team committed to innovation and excellence in cybersecurity.

Responsibilities

Design and develop impactful SIEM use cases specifically for OT environments. Onboard diverse data sources into the SIEM, creating custom parsers for unsupported sources and ensuring data verification against the Common Information Model (CIM).

Develop expertise in parsing and masking data before ingestion, and provide comprehensive support for data collection, processing, analysis, and operational reporting systems. This includes planning, installation, configuration, testing, troubleshooting, and problem resolution.

Collaborate with clients to optimize SIEM system capabilities and audit logging features. Offer technical guidance for configuring end log sources for seamless SIEM integration. Create advanced visualizations and dashboards for near real-time visibility into OT applications.

Provide operational support for globally deployed OT network monitoring solutions such as Nozomi, Claroty, and Armis. Demonstrate strong programming or scripting skills, particularly in Python and JavaScript, along with Bash and PowerShell.

Offer consulting services during testing, evaluation, pilot, production, and training phases to ensure successful SIEM deployments. Understand client requirements and recommend best practices for SIEM solutions, providing consultative advice on security principles and SIEM operations. Design and document SIEM solutions tailored to client needs.

Develop automated security event monitoring and alerting processes, including corresponding event response plans. Create use cases aligned with the Cyber Kill Chain and MITRE ATT&CK Framework. Configure alerts and reports effectively, and tune SIEM rules to meet client-specific alert and incident requirements.

Work closely with client points of contact for correlation rule tuning, incident classification, and prioritization recommendations, adhering to the use case management lifecycle.

Qualifications

We are looking for a seasoned professional with a minimum of 8 years in cybersecurity, including at least 4 years focused on OT/IoT Security solutions. A strong understanding of IT/OT/IoT communication protocols and experience supporting industrial protocols is essential.

Exceptional oral, written, and listening skills are required for effective client consulting. A robust background in network administration is necessary, with the ability to articulate communication at any layer of the OSI model. Knowledge of Vulnerability Management, Windows and Linux fundamentals (including installations, domains, trusts, GPOs, server roles, security policies, and user administration) is also crucial.

Experience with designing and implementing Splunk, focusing on IT Operations, Application Analytics, User Experience, Application Performance, and Security Management is highly desirable. This includes experience with multiple cluster deployments and management following vendor guidelines and best practices. The ability to troubleshoot Splunk platform and application issues, escalate effectively, and work with Splunk support is also valued.

Certifications in any leading SIEM solution (e.g., Splunk, IBM QRadar, Exabeam, Securonix) or a core security-related discipline will be considered an added advantage. This role demands a proactive approach to security and a commitment to delivering high-quality solutions.

Essential Skills

SIEMOT SecurityThreat DetectionLog AnalysisData OnboardingCustom ParsersCommon Information Model (CIM)Data MaskingPythonJavaScriptBashPowerShellCyber Kill ChainMITRE ATT&CK FrameworkAlertingReportingSplunkNetwork AdministrationVulnerability ManagementWindowsLinux

Good to Have

NozomiClarotyArmisSplunk CertificationSIEM Solution Certification

Highlights

  • Actively hiring

More Details

RoleTC - CS - CDR - SIEM Content Developer - Senior
IndustryInformation Technology & Services, Cybersecurity, Management Consulting
DepartmentInformation Technology, Security, Engineering
Employment TypeFull Time, Hybrid (office + remote)

About the Company

EY Global Delivery Services ( EY GDS) logo

EY Global Delivery Services ( EY GDS)

Information Technology & Services

TC - CS - CDR - SIEM Content Developer - Senior at EY | SkillMX | SkillMX