Apply now »

TC-CS-CDR-NG SIEM-Manager

Location:  Hyderabad
Other locations:  Anywhere in Country
Salary: Competitive
Date:  Jul 3, 2026

Job description

Requisition ID:  1696271

At EY, we’re all in to shape your future with confidence. 

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. 

Join EY and help to build a better working world. 

 

NGSIEM JD details for Manager

 

Manager

 

Role Summary

The NG SIEM Manager owns the enterprise-wide SIEM–SOAR strategy, including ingestion architecture, detection governance, correlation frameworks (Fusion), and case management standards. This leadership role drives automation maturity, data quality, and operational excellence across Security Engineering.

 

Key Responsibilities

  • Define overall NG SIEM and SOAR strategy, roadmap, and architecture.
  • Govern onboarding, ingestion structures, and quality standards using Cribl, cloud-native pipelines, and routing rules.
  • Establish Fusion correlation strategy—priority rule sets, enrichment patterns, MITRE coverage, noise control.
  • Lead the enterprise Case Management program (workflow, SLA, severity model, automation).
  • Own SOAR strategy—automation roadmap, playbook standards, orchestration framework, KPIs.
  • Partner with IR, Threat Hunting, CTI, Cloud Security, and Network teams to design multi-layer detection logic.
  • Review and approve critical detection content, correlation logic, and data models.
  • Oversee ingestion performance, retention, licensing, and cost optimization.
  • Manage a team of Staff, Senior Engineers, and Automation Engineers.
  • Present metrics and maturity dashboards to leadership:
    • ingestion health
    • correlation performance
    • case SLA adherence
    • automation success rate
  • Drive continuous improvement, runbooks, SOPs, and audit readiness.
  • Experience or exposure to AI‑powered SOC features such as Charlotte AI, Sentinel Copilot.
  • Ability to leverage AI assistants for query generation (SPL/KQL/CQL), alert summarization, detection tuning, and workflow optimization.
  • Familiarity with exploring AI capabilities in SOAR platforms (Fusion, Sentinel, Splunk SOAR) to automate enrichment, case resolution, and noise reduction.

 

Skills & Experience

  • 7+ years in SIEM/SOAR, detection engineering, or security analytics.
  • Expertise in Fusion-like correlation engines, case management frameworks, and SOAR automation.
  • Strong background in security architecture, data modeling, and cross-platform integrations.
  • Experience managing teams and multi-stakeholder programs.
  • Deep hands-on knowledge of Cribl, cloud-native pipelines, Falcon NGSIEM, Sentinel, ADX, Splunk, LogScale.
  • Strong communication and executive presentation skills.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

Apply now »