SIEM Engineer - Senior – EY GDS Spain - Hybrid
The opportunity
Are you ready to shape your future with confidence?
As a Senior SIEM Engineer, you are part of the EY Cyber Security team, working in a Threat Detection & Response (TDR) environment with a strong focus on Microsoft Sentinel and XDR. You design, integrate, and operate SIEM use cases and automations and support clients in securely operating modern cloud-native security platforms. Knowledge of Splunkor open-source SIEM ecosystems (e.g., Elastic/ELK, Wazuh) is considered a strong advantage.
As a member of our team in the EY GDS Spain office in Malaga, you’ll have a chance to extend your knowledge & experience by working on interesting projects with the latest technologies and approaches. You’ll support clients in choosing the most suitable business solution and take part in digital transformation.
Your key responsibilities
· Integrate data sources into Microsoft Sentinel (cloud, identity, endpoint, network, and on-prem) and ensure data quality and normalization.
· Design, implement, and operate analytics rules, SIEM use cases, and hunting queries (KQL; SPL experience is a plus).
· Develop and maintain playbooks and automations using Azure Logic Apps to enrich, orchestrate, and standardize response workflows.
· Act as a technical subject matter expert for SIEM and Microsoft Sentinel/XDR solutions and provide hands-on guidance to stakeholders.
Optimize SOC Operations leveraging the latest AI capabilities
· Continuously optimize detection, response, and automation capabilities (tuning, false-positive reduction, performance, and maintainability).
· Contribute to engineering best practices such as documentation, repeatable deployments, and (where applicable) detection/content as code.
Skills and attributes for success
· Strong knowledge of cloud security concepts, SIEM architectures, and the MITRE ATT&CK framework.
· Hands-on engineering mindset with solid troubleshooting, analytical thinking, and attention to detail.
· Pragmatic communicator who can translate complex technical topics into actionable recommendations for different audiences.
· Ownership and quality focus: audit-ready documentation, structured delivery, and continuous improvement.
Curiosity on new technologies and approaches and readiness to constantly develop and reinvent the way we work
To qualify for the role, you must have
· 2 - + 4 years of experience in SIEM engineering (design, onboarding, use case development, tuning, and operations), ideally with Microsoft Sentinel.
· Hands-on experience with Azure, Windows/Linux, and scripting (e.g., Python, PowerShell, Bash) as well as automation concepts.
· Experience building or operating SOAR-style automations (e.g., Logic Apps / playbooks) in a security operations context.
· English at least B2 (written and spoken) is required.
Ideally, you’ll also have
· Splunk experience (SPL, data onboarding, correlations, dashboards) and/or open-source SIEM experience (e.g., Elastic/ELK, Wazuh).
· Experience working in regulated environments and familiarity with operational processes (ITSM, incident workflow alignment).
· Relevant certifications (e.g., SC-200, AZ-500, or comparable cloud/security certifications) are a plus.
What we look for:
We look for engineers who build detections that stand up in real operations—reliable, scalable, and automated where it matters. You take ownership, collaborate across teams and time zones, and continuously improve signal quality from data onboarding to response workflows.
What we offer
In EY GDS Spain, we’re committed to fostering a vibrant environment where every team member can thrive. We provide a space for continuous learning and the flexibility of a hybrid work model. Our culture values inclusion, professional development, wellbeing, volunteering opportunities, and recognition of performance.
Additionally, here’s what makes us stand out:
Join us at EY GDS Spain, where your journey is supported, your contributions are celebrated, and your future is bright.
To learn more about what we offer, visit our Careers in Global Delivery Services | EY - Global
About EY GDS
EY Global Delivery Services (EY GDS) is a dynamic and truly global delivery network of over 75,000 people working across the world, to provide innovative and strategic business solutions to our clients worldwide. We play a vital role in growth strategy, helping our clients become agile and efficient, and helping fulfill our purpose to build a better working world.
From accountants to coders, we offer a wide variety of fulfilling career opportunities that span all business disciplines. We look for skills that are evergreen and our roles evolve with industry trends. We also work across Finance, Business Development, Technology, Talent, Procurement and Risk Management functions to help our teams operate as efficiently and effectively as possible.
Across our 10 locations and 21 cities, we work with teams from all service lines, geographies, and sectors. We operate in Argentina, Hungary, India, the Philippines, Poland, Sri Lanka, Mexico, Spain and the United Kingdom.
Our EY GDS Spain office is located at Malaga Technology Park and currently employs over 1000 people.
If you are interested in being part of our team, we kindly invite you to submit your CV in English to apply for this position.
The exceptional EY GDS experience. It’s yours to build.

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams in more than 150 countries work across a full spectrum of services in assurance, consulting, tax, strategy and transactions, strengthened by sector experience and diverse ecosystem partners.
Find out more about the EY global network: http://ey.com/en_gl/legal-statement