Senior Associate, SIEM Implementation

Posted 3 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • SIEM implementation leader delivering cybersecurity solutions for PwC Canada clients. Building detections, integrations, data pipelines, and SOAR workflows across major security platforms.

Responsibilities

  • Lead technical deliverables for SIEM implementation and operations using Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, and Devo
  • Perform Proof of Concept and Proof of Value engagements
  • Conduct SIEM assessments, identify gaps, recommend improvements, and align with security best practices
  • Develop and maintain data pipelines for log ingestion, normalization, and enrichment across cloud and on-premises environments
  • Integrate log sources using connectors, custom scripts, and parsers
  • Build use cases aligned with NIST and MITRE ATT&CK frameworks
  • Implement SPL/KQL detection rules with complex cross-source correlation
  • Develop dashboards, alerts, and workbooks for security monitoring and reporting
  • Implement SOAR workflows using Logic Apps, Phantom, Demisto, and XSOAR
  • Perform SIEM health checks, tuning, and optimization
  • Create and maintain SOPs, runbooks, architecture diagrams, and onboarding guides
  • Collaborate with SOC, threat hunting, infrastructure, and cloud teams
  • Deploy SIEM content through GitHub CI/CD pipelines and support operational readiness activities
  • Develop custom SIEM integrations, including scripts, APIs, parsers, data transformation logic, and DataBahn pipeline management
  • Apply AI capabilities to improve detection engineering, content optimization, operational efficiency, and analytical outcomes

Requirements

  • Bachelor's degree in computer science, Cybersecurity, or related field
  • Minimum 3 years of experience in SIEM implementation and security operations
  • Hands-on experience with Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, Devo, and Splunk
  • Strong understanding of SIEM architecture, implementation, integration, log management, and threat detection methodologies
  • Experience developing and tuning security use cases and alerts
  • Proficiency in Python, PowerShell, and Bash
  • Experience with Azure, GCP, and AWS
  • Knowledge of Cribl for log routing, enrichment, and deduplication
  • Familiarity with REST APIs, JSON, and third-party security tool integrations
  • Experience with SOAR platforms and playbook development
  • Understanding of cyber-attacks, threat vectors, risk management, and incident management
  • Experience deploying SIEM content through CI/CD practices using GitHub
  • Experience managing security data pipelines and ingestion workflows, including DataBahn
  • Strong understanding of AI concepts and tools for security-oriented use cases
  • Proficiency in Microsoft Office tools, especially Excel, Word, PowerPoint, Teams, and Outlook
  • Demonstrated ability to work collaboratively across teams and manage multiple client engagements
  • Preferred certifications: Microsoft Certified: Security Operations Analyst Associate, SC-200, AZ-500, Google Professional Cloud Security Engineer, CISSP, CISM, GIAC
  • Experience in a consulting, client delivery, or professional services environment is preferred
  • No work visa sponsorship available

Benefits

  • Variable incentive pay programs for eligible employees
  • Competitive compensation package
  • Inclusive benefits
  • Flexibility programs
  • Comprehensive total rewards package
  • Inclusive, hybrid work environment
  • Accommodation throughout the application, interview, and employment process

Job title

Job type

Full Time

Experience level

Senior

Salary

CA$84,700 - CA$134,700 per year

Degree requirement

Bachelor's Degree

Tech skills

AWSAzureCloudCyber SecurityGoogle Cloud PlatformPythonSplunk

Location requirements

HybridTorontoCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.