Padmi

Next-Gen SIEM Security Analyst (Thiruvananthapuram)

IndiaPosted 2 months ago
CybersecurityJuniorFull Time; Regular
Apply at Ernst & Young LLP ( EY India )

Opens the source posting on shine.com

Source description

About the role

View original

TC-CS-CDR-NG SIEM-Staff At EY, were all in to shape your future with confidence. Well help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. NGSIEM JD details for Staff Staff : Role Summary The NG SIEM Staff role supports monitoring, log onboarding, and basic detection engineering across up-to-date SIEM ecosystems. The role also assists in case management activities, workflows, and basic SOAR playbook operations. Key Responsibilities Support end-to-end onboarding of log sources into NG SIEM via Cribl, Syslog, cloud connectors. Validate parsing, normalization, and schema mapping. Assist in writing basic detection queries (SPL/KQL/CQL). Perform case creation, triage, assignment, and closure using SIEM Case Management module. Review correlation events generated by Fusion engines and escalate anomalies. Trigger and monitor SOAR playbooks for routine alert handling. Participate in alert enrichment, tagging, and case documentation. Troubleshoot ingestion, worker group issues, queue delays, and missing logs. Support operational runbooks and SOP documentation. Ensure logs and detections align with MITRE ATT&CK.; Exposure to nextgen SIEM AI features such as Charlotte AI for query generation, detections troubleshooting, and search assistance. Basic understanding of AI-driven features in Sentinel & Copilot, including assisted incident summarization and automated enrichment. Handson interest in exploring AI capabilities of SOAR platforms such as Fusion or Sentinel SOAR to speed up investigation tasks. Skills & Experience Knowledge of SIEM, SOC workflows, detection lifecycle. Experience using Case Management tools (Falcon NGSIEM, Sentinel Incident Hub, Splunk ES). Basic understanding of SOAR automation (CrowdStrike Fusion, Sentinel SOAR, Splunk SOAR). Hands-on with at least one query language (SPL/KQL/CQL). Familiarity with cloud and firewall log sources. TC-CS-CDR-NG SIEM-Staff At EY, were all in to shape your future with confidence. Well help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. NGSIEM JD details for Staff Staff : Role Summary The NG SIEM Staff role supports monitoring, log onboarding, and basic detection engineering across up-to-date SIEM ecosystems. The role also assists in case management activities, workflows, and basic SOAR playbook operations. Key Responsibilities Support end-to-end onboarding of log sources into NG SIEM via Cribl, Syslog, cloud connectors. Validate parsing, normalization, and schema mapping. Assist in writing basic detection queries (SPL/KQL/CQL). Perform case creation, triage, assignment, and closure using SIEM Case Management module. Review correlation events generated by Fusion engines and escalate anomalies. Trigger and monitor SOAR playbooks for routine alert handling. Participate in alert enrichment, tagging, and case documentation. Troubleshoot ingestion, worker group issues, queue delays, and missing logs. Support operational runbooks and SOP documentation. Ensure logs and detections align with MITRE ATT&CK.; Exposure to nextgen SIEM AI features such as Charlotte AI for query generation, detections troubleshooting, and search assistance. Basic understanding of AI-driven features in Sentinel & Copilot, including assisted incident summarization and automated enrichment. Handson interest in exploring AI capabilities of SOAR platforms such as Fusion or Sentinel SOAR to speed up investigation tasks. Skills & Experience Knowledge of SIEM, SOC workflows, detection lifecycle. Experience using Case Management tools (Falcon NGSIEM, Sentinel Incident Hub, Splunk ES). Basic understanding of SOAR automation (CrowdStrike Fusion, Sentinel SOAR, Splunk SOAR). Hands-on with at least one query language (SPL/KQL/CQL). Familiarity with cloud and firewall log sources.

One address, no account. We’ll tell you when matching roles go live.

More at Ernst & Young LLP ( EY India )

Related open roles

View all roles