SIEM Engineer - Senior - EY GDS Hybrid
Publicado en 2026-09-26
-
TI/Tecnología
Seguridad cibernética, Ingeniero de sistemas
Location:
Malaga
Other locations:
Primary Location Only
Date:
Sep 5, 2026
Requisition
The opportunityAre you ready to shape your future with confidence?
As a Senior SIEM Engineer, you are part of the EY Cyber Security team, working in a Threat Detection & Response (TDR) environment with a strong focus on Microsoft Sentinel and XDR. You design, integrate, and operate SIEM use cases and automations and support clients in securely operating modern cloud-native security platforms. Knowledge of
Splunk
or
open-source SIEM ecosystems (e.g., Elastic/ELK, Wazuh) is considered a strong advantage.
As a member of our team in the EY GDS Spain office in Malaga
, you’ll have a chance to extend your knowledge & experience by working on interesting projects with the latest technologies and approaches. You’ll support clients in choosing the most suitable business solution and take part in digital transformation.
· Integrate data sources into Microsoft Sentinel (cloud, identity, endpoint, network, and on-prem) and ensure data quality and normalization.
· Design, implement, and operate analytics rules, SIEM use cases, and hunting queries (KQL; SPL experience is a plus).
· Develop and maintain playbooks and automations using Azure Logic Apps to enrich, orchestrate, and standardize response workflows.
· Act as a technical subject matter expert for SIEM and Microsoft Sentinel/XDR solutions and provide hands-on guidance to stakeholders.
Optimize SOC Operations leveraging the latest AI capabilities
· Continuously optimize detection, response, and automation capabilities (tuning, false-positive reduction, performance, and maintainability).
· Contribute to engineering best practices such as documentation, repeatable deployments, and (where applicable) detection/content as code.
Skills and attributes for success· Strong knowledge of cloud security concepts, SIEM architectures, and the MITRE ATT&CK framework.
· Hands-on engineering mindset with solid troubleshooting, analytical thinking, and attention to detail.
· Pragmatic communicator who can translate complex technical topics into actionable recommendations for different audiences.
· Ownership and quality focus: audit-ready documentation, structured delivery, and continuous improvement.
Curiosity on new technologies and approaches and readiness to constantly develop and reinvent the way we work
To qualify for the role, you must have· 2 - + 4 years of experience in SIEM engineering (design, onboarding, use case development, tuning, and operations), ideally with Microsoft Sentinel.
· Hands-on experience with Azure , Windows/Linux, and scripting (e.g., Python, Power Shell, Bash) as well as automation concepts.
· Experience building or operating SOAR-style automations (e.g., Logic Apps / playbooks) in a security operations context.
· English at least B2 (written and spoken) is required.
· Splunk experience (SPL, data onboarding, correlations, dashboards) and/or open-source SIEM experience (e.g.,
Elastic/ELK, Wazuh).
· Experience working in regulated environments and familiarity with operational processes (ITSM, incident workflow alignment).
·
Relevant certifications (e.g., SC-200, AZ-500, or comparable cloud/security certifications) are a plus.
We look for engineers who build detections that stand up in real operations—reliable, scalable, and automated where it matters. You take ownership, collaborate across teams and time zones, and continuously improve signal quality from data onboarding to response workflows.
What we offerIn EY GDS Spain, we’re committed to fostering a vibrant environment where every team member can thrive. We provide a space for continuous learning and the flexibility of a hybrid work model. Our culture…
(Si este trabajo está en su jurisdicción, entonces puede estar usando un Proxy o VPN para acceder a este sitio, para seguir avanzando, debe cambiar su conectividad a otro dispositivo móvil o PC).