Senior Siem Engineer - Ey Gds Spain - Hybrid

Ernst & Young Global Limited
Madrid, Spain
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Microsoft Windows Microsoft Azure Bash Shell Cloud Computing Security Cyber Security Linux Intrusion Detection and Prevention Python (Programming Language) Open Source Technology Performance Tuning Windows PowerShell Kusto Query Language
+7 more
Security Information and Event Management Scripting Data Ingestion Microsoft Power Automate Mitre Att&ck Microsoft Sentinel Splunk

Job description

SIEM Engineer - Senior - EY GDS Spain - HybridAs a Senior SIEM Engineer, you are part of the EY Cyber Security team, working in a Threat Detection & Response (TDR) environment with a strong focus on Microsoft Sentinel and XDR.You design, integrate, and operate SIEM use cases and automations and support clients in securely operating modern cloud-native security platforms.Knowledge of Splunk or open-source SIEM ecosystems (e.g., Elastic/ELK, Wazuh) is considered a strong advantage.Your Key ResponsibilitiesIntegrate data sources into Microsoft Sentinel (cloud, identity, endpoint, network, and on-prem) and ensure data quality and normalization.Design, implement, and operate analytics rules, SIEM use cases, and hunting queries (KQL; SPL experience is a plus).Develop and maintain playbooks and automations using Azure Logic Apps to enrich, orchestrate, and standardize response workflows.Act as a technical subject matter expert for SIEM and Microsoft Sentinel/XDR solutions and provide hands?on guidance to stakeholders.Optimize SOC OperationsContinuously optimize detection, response, and automation capabilities (tuning, false?positive reduction, performance, and maintainability).Contribute to engineering best practices such as documentation, repeatable deployments, and (where applicable) detection/content as code.Skills and Attributes for SuccessStrong knowledge of cloud security concepts, SIEM architectures, and the MITRE ATT&CK framework.Hands?on engineering mindset with solid troubleshooting, analytical thinking, and attention to detail.Pragmatic communicator who can translate complex technical topics into actionable recommendations for different audiences.Ownership and quality focus: audit?ready documentation, structured delivery, and continuous improvement.To Qualify for the Role2 - + 4 years of experience in SIEM engineering (design, onboarding, use case development, tuning, and operations), ideally with Microsoft Sentinel.Hands?on experience with Azure, Windows/Linux, and scripting (e.g., Python, PowerShell, Bash) as well as automation concepts.Experience building or operating SOAR?style automations (e.g., Logic Apps / playbooks) in a security operations context.English at least B2 (written and spoken) is required.Ideally you’d also haveSplunk experience (SPL, data onboarding, correlations, dashboards) and/or open-source SIEM experience (e.g., Elastic/ELK, Wazuh).Experience working in regulated environments and familiarity with operational processes (ITSM, incident workflow alignment).Relevant certifications (e.g., SC-200, AZ?500, or comparable cloud/security certifications) are a plus.#J-*****-Ljbffr

Requirements

Strong knowledge of cloud security concepts, SIEM architectures, and the MITRE ATT&CK framework. Hands?on engineering mindset with solid troubleshooting, analytical thinking, and attention to detail. Pragmatic communicator who can translate complex technical topics into actionable recommendations for different audiences. Ownership and quality focus: audit?ready documentation, structured delivery, and continuous improvement. To Qualify for the Role 2 - + 4 years of experience in SIEM engineering (design, onboarding, use case development, tuning, and operations), ideally with Microsoft Sentinel. Hands?on experience with Azure, Windows/Linux, and scripting (e.g., Python, PowerShell, Bash) as well as automation concepts. Experience building or operating SOAR?style automations (e.g., Logic Apps / playbooks) in a security operations context. English at least B2 (written and spoken) is required. Ideally you’d also have Splunk experience (SPL, data onboarding, correlations, dashboards) and/or open-source SIEM experience (e.g., Elastic/ELK, Wazuh). Experience working in regulated environments and familiarity with operational processes (ITSM, incident workflow alignment). Relevant certifications (e.g., SC-200, AZ?500, or comparable cloud/security certifications) are a plus. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all