TC-CS-CDR-NG SIEM-Staff
Job description
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
NGSIEM JD details for Staff
Staff :
Role Summary
The NG SIEM Staff role supports monitoring, log onboarding, and basic detection engineering across modern SIEM ecosystems. The role also assists in case management activities, workflows, and basic SOAR playbook operations.
Key Responsibilities
- Support end-to-end onboarding of log sources into NG SIEM via Cribl, Syslog, cloud connectors.
- Validate parsing, normalization, and schema mapping.
- Assist in writing basic detection queries (SPL/KQL/CQL).
- Perform case creation, triage, assignment, and closure using SIEM Case Management module.
- Review correlation events generated by Fusion engines and escalate anomalies.
- Trigger and monitor SOAR playbooks for routine alert handling.
- Participate in alert enrichment, tagging, and case documentation.
- Troubleshoot ingestion, worker group issues, queue delays, and missing logs.
- Support operational runbooks and SOP documentation.
- Ensure logs and detections align with MITRE ATT&CK.
- Exposure to next‑gen SIEM AI features such as Charlotte AI for query generation, detections troubleshooting, and search assistance.
- Basic understanding of AI-driven features in Sentinel & Copilot, including assisted incident summarization and automated enrichment.
- Hands‑on interest in exploring AI capabilities of SOAR platforms such as Fusion or Sentinel SOAR to speed up investigation tasks.
Skills & Experience
- Knowledge of SIEM, SOC workflows, detection lifecycle.
- Experience using Case Management tools (Falcon NGSIEM, Sentinel Incident Hub, Splunk ES).
- Basic understanding of SOAR automation (CrowdStrike Fusion, Sentinel SOAR, Splunk SOAR).
- Hands-on with at least one query language (SPL/KQL/CQL).
- Familiarity with cloud and firewall log sources.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.