yoinka

Senior Associate SIEM Implementation

PricewaterhouseCoopers

TorontoMidH-1B sponsor company
Sign in to applyVerified 3h ago
Location
Toronto
Work model
On-Site
Level
Mid
H-1B history
236 approvals (FY2023)
Posted
Aug 24, 2026

Skills

AWSAzureCI/CDCybersecurityGCPGitPythonRESTShellSplunk

About this role

Line of Service Advisory Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Manager Job Description & Summary At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. As a cybersecurity generalist at PwC, you will focus on providing comprehensive security solutions and experience across various domains, maintaining the protection of client systems and data. You will apply a broad understanding of cybersecurity principles and practices to address diverse security challenges effectively.

The Opportunity

As a   Senior Associate SIEM Implementation,   u nlock your potential and embrace the chance to drive meaningful outcomes   that ’ ll   elevate your career. Your role will include, but   is n’ t   limited to:   Lead technical deliverables for SIEM implementation and operations including Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, and Devo.    Perform Proof of Concept (PoC) and Proof of Value (PoV) engagements to evaluate SIEM capabilities and   demonstrate   value to stakeholders.    Conduct SIEM assessments to   identify   gaps, recommend improvements, and align with security best practices.    Develop and   maintain   data pipelines for log ingestion, normalization, and enrichment across cloud and on-prem environments.    Integrate log sources using connectors, custom scripts, and parsers to ensure complete visibility and compatibility with SIEM platforms.    Build use cases aligned with NIST and MITRE ATT&CK frameworks to enable detection at various stages of a cyber-attack.    Implement detection rules using SPL/KQL with complex correlation across different data sources.    Develop dashboards, alerts, and workbooks for security monitoring and reporting.    Implement SOAR workflows using Logic Apps, Phantom,   Demisto , and XSOAR platforms.    Perform health checks, tuning, and optimization of SIEM platforms to ensure high performance and accuracy.    Create and   maintain   documentation including SOPs, runbooks, architecture diagrams, and onboarding guides.    Collaborate with cross-functional teams including SOC, threat hunters, infrastructure, and cloud teams to support delivery and ensure quality standards.    Lead technical deliverables for SIEM implementation and security operations engagements, including log source onboarding, parser development, SIEM content   deployment through CI/CD pipelines using GitHub, detection use case implementation, and operational readiness activities.    Develop and support custom integrations to SIEM platforms, especially Microsoft Sentinel and Google SecOps, including scripts, APIs, parsers, data transformation logic, and data pipeline management activities such as   DataBahn .    Apply AI capabilities in a security-focused manner to improve   detection   engineering, content optimization, operational efficiency, and analytical outcomes while   maintaining   strong security and governance awareness.

What You'll Bring

Your skills, knowledge, and experiences are what set you apart.   Here's   what we look for:   Hands-on experience with Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, Devo, and Splunk.    Strong understanding of SIEM architecture, implementation, integration, log management, and threat detection methodologies.    Experience in developing and tuning security use cases and alerts.    Proficiency   in scripting languages such as Python, PowerShell, and Bash for automation and data processing.    Experience with cloud platforms including Azure, GCP, and AWS.    Knowledge of data pipeline tools including   Cribl   for log routing, enrichment, and deduplication.    Familiarity with REST APIs, JSON, and integration of third-party

Listing verified 3h ago. Applications go through the company's official careers site.

← Back to Yoinka

Senior Associate SIEM Implementation at PricewaterhouseCoopers, Toronto | Yoinka