Cyber SDC - SIEM Engineer - Senior - Consulting - Location Open
Dallas, TX, US, 75219
EY
Mit unseren vier integrierten Geschäftsbereichen — Wirtschaftsprüfung und prüfungsnahe Dienstleistungen, Steuerberatung, Unternehmensberatung und Strategy and Transactions — sowie unserem Branchenwissen unterstützen wir unsere Mandanten dabei,...In today's fast-evolving cybersecurity landscape, businesses across all sectors rely on us to provide reliable solutions to their growingly intricate risks and vulnerabilities. As part of our Cyber Threat and Vulnerability Management (TVM) team you will play a pivotal role in achieving this objective. You will assist our clients in understanding and contextualizing their cybersecurity threats, as well as in evaluating, enhancing, and developing their security operations to counter these threats effectively. Leveraging both your technical expertise and business acumen, you will contribute significantly to our mission, making a global impact on cybersecurity.
The opportunity
Cybersecurity threats, the proliferation of social media, extensive data storage demands, stringent privacy laws, and the necessity for uninterrupted business operations all mandate robust information security strategies. In the role of an information security specialist, you will spearhead the deployment of cutting-edge security solutions for our clients, aiding them in safeguarding their enterprises. You will be an integral part of a globally interconnected team of experts dedicated to addressing our clients' most challenging information security issues, thereby enhancing their organizational resilience. Collaborating with our Advanced Security Centers, you will have access to the most advanced tools to combat cybercrime effectively.
EY commits to your professional growth through comprehensive, ongoing training and coaching, ensuring the development of your skills throughout your career. As a leading global service provider in this field, you will collaborate with top-tier professionals in a supportive environment. Joining EY means embarking on a journey where, regardless of how long you're with us, the exceptional EY experience will enrich your professional life forever.
What to Expect
Our security experts are distinguished by their broad industry insights, exceptional technical know-how, and specialized abilities. They maintain their cutting-edge relevance by continuously uncovering the latest security vulnerabilities, engaging with leading security conferences globally as attendees and speakers, and disseminating their knowledge across a range of subjects to essential industry bodies. Through a mix of conventional and innovative means—including conference presentations, white paper publications, and blogging—our team consistently leads in providing thought leadership and fostering information sharing.
Together, our professionals engage in a collaborative process to strategize, execute, and oversee projects aimed at evaluating, enhancing, and, in certain instances, managing our clients' comprehensive security operations. This teamwork ensures the provision of advanced, integrated security solutions tailored to our clients' specific needs.
Your Key Responsibilities
- Deliver exceptional client services with a focus on Advanced SIEM Platforms. Monitor project progress diligently, manage potential risks, and keep key stakeholders updated on progress and expected outcomes. Stay informed about the latest business and industry trends, especially those relevant to cybersecurity and the client's business.
- Build and maintain strong business relationships with client personnel, positioning yourself as a trusted advisor in the implementation and management of solutions.
- Demonstrate technical expertise and professional knowledge. Show an eagerness to absorb new knowledge and adapt to emerging technologies in cybersecurity.
- Exhibit strong business acumen with an understanding of the strategic importance of SIEM technologies in protecting the client's business operations.
- Stay updated on the latest advancements in advisory services capabilities and broader industry knowledge.
- Apply a thorough understanding of complex information systems, leveraging your expertise in the current IT environment and industry trends to identify issues in client engagements. Effectively communicate these insights to both the engagement team and client management through clear written correspondence and articulate verbal presentations.
- Possess a thorough understanding of the incident response process and familiarity with frameworks like MITRE ATT&CK to enhance threat detection and response capabilities.
To qualify for the role you must have
- A Bachelor's degree and a minimum of 4 years of related work experience, or a Master’s degree and approximately 3 years of related work experience in the fields of Computer Science, Information Systems, Engineering, Business, or a related major.
- A minimum of 1 year of related work experience with information security systems, including hands-on SIEM technical infrastructure and implementation experience.
- Knowledge of general security concepts and methods, such as vulnerability assessments, privacy assessments, intrusion detection, incident response, the MITRE ATT&CK Framework, security policy creation, enterprise security strategies, architectures, and governance.
- Experience in leading process definition, workflow design, and process mapping, with an emphasis on integrating SIEM and SOAR capabilities into business operations.
- An understanding of networking (TCP/IP, OSI model), operating system fundamentals (Windows, UNIX, mainframe), security technologies (firewalls, IDS/IPS, etc.), and application programming/scripting languages (C, Java, Perl, Shell).
- A valid driver's license in the US and a valid passport are required.
Ideally, you’ll also have
- Experience implementing and building SOAR Capability
- Experience with Windows, Linux, UNIX, any other major operating systems.
- Understanding of AI Security tools
- Prior Consulting Experience
- Experience with programming in Python, C, Java, Perl, Shell and/or bash shell scripting.
- Familiarity with REST API best practices and usage
- Familiarity with security technologies (Cloud, DLP, firewalls, IDS/IPS, EDR, etc.) and other SOAR products (Falcon Fusion, Splunk SOAR, Google Chronicle SecOps, LogicApps, Sentinel, etc.)
- CISSP, CISM, CISA, CIPT, CIPM, CRISC or other relevant certification desired
What We Look For
We’re interested in intellectually curious people with a genuine passion for cyber security. With your expertise with advanced SIEM platforms, we’ll turn to you to speak up with innovative new ideas that could make a lasting difference not only to us – but also to the industry as a whole. If you have the confidence in both your presentation and technical abilities to grow into a leading expert here, this is the role for you.
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
Tags: APIs Bash C CISA CISM CISSP Cloud Computer Science CRISC Cyber crime EDR Firewalls Governance IDS Incident response Intrusion detection IPS Java Linux Mainframe MITRE ATT&CK Perl Privacy Python REST API Scripting SecOps Sentinel SIEM SOAR Splunk Strategy TCP/IP Threat detection UNIX Vulnerabilities Vulnerability management Windows
Perks/benefits: Career development Conferences Flex hours Flex vacation Health care
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.