At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. As a cybersecurity generalist at PwC, you will focus on providing comprehensive security solutions and experience across various domains, maintaining the protection of client systems and data. You will apply a broad understanding of cybersecurity principles and practices to address diverse security challenges effectively. The Opportunity As a Senior Associate SIEM Implementation, unlock your potential and embrace the chance to drive meaningful outcomes that’ll elevate your career. Your role will include, but isn’t limited to: Lead technical deliverables for SIEM implementation and operations including Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, and Devo. Perform Proof of Concept (PoC) and Proof of Value (PoV) engagements to evaluate SIEM capabilities and demonstrate value to stakeholders. Conduct SIEM assessments to identify gaps, recommend improvements, and align with security best practices. Develop and maintain data pipelines for log ingestion, normalization, and enrichment across cloud and on-prem environments. Integrate log sources using connectors, custom scripts, and parsers to ensure complete visibility and compatibility with SIEM platforms. Build use cases aligned with NIST and MITRE ATT&CK frameworks to enable detection at various stages of a cyber-attack. Implement detection rules using SPL/KQL with complex correlation across different data sources. Develop dashboards, alerts, and workbooks for security monitoring and reporting. Implement SOAR workflows using Logic Apps, Phantom, Demisto, and XSOAR platforms. Perform health checks, tuning, and optimization of SIEM platforms to ensure high performance and accuracy. Create and maintain documentation including SOPs, runbooks, architecture diagrams, and onboarding guides. Collaborate with cross-functional teams including SOC, threat hunters, infrastructure, and cloud teams to support delivery and ensure quality standards. Lead technical deliverables for SIEM implementation and security operations engagements, including log source onboarding, parser development, SIEM content deployment through CI/CD pipelines using GitHub, detection use case implementation, and operational readiness activities. Develop and support custom integrations to SIEM platforms, especially Microsoft Sentinel and Google SecOps, including scripts, APIs, parsers, data transformation logic, and data pipeline management activities such as DataBahn. Apply AI capabilities in a security-focused manner to improve detection engineering, content optimization, operational efficiency, and analytical outcomes while maintaining strong security and governance awareness.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior