About the Role
As a cybersecurity generalist at PwC, you will focus on providing comprehensive security solutions and experience across various domains, maintaining the protection of client systems and data. You will apply a broad understanding of cybersecurity principles and practices to address diverse security challenges effectively.
Responsibilities
- Lead technical deliverables for SIEM implementation and operations including Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, and Devo.
- Perform Proof of Concept (PoC) and Proof of Value (PoV) engagements to evaluate SIEM capabilities and demonstrate value to stakeholders.
- Conduct SIEM assessments to identify gaps, recommend improvements, and align with security best practices.
- Develop and maintain data pipelines for log ingestion, normalization, and enrichment across cloud and on-prem environments.
- Integrate log sources using connectors, custom scripts, and parsers to ensure complete visibility and compatibility with SIEM platforms.
- Build use cases aligned with NIST and MITRE ATT&CK frameworks to enable detection at various stages of a cyber-attack.
- Implement detection rules using SPL/KQL with complex correlation across different data sources.
- Develop dashboards, alerts, and workbooks for security monitoring and reporting.
- Implement SOAR workflows using Logic Apps, Phantom, Demisto, and XSOAR platforms.
- Perform health checks, tuning, and optimization of SIEM platforms to ensure high performance and accuracy.
- Create and maintain documentation including SOPs, runbooks, architecture diagrams, and onboarding guides.
- Collaborate with cross-functional teams including SOC, threat hunters, infrastructure, and cloud teams to support delivery and ensure quality standards.
- Lead technical deliverables for SIEM implementation and security operations engagements, including log source onboarding, parser development, SIEM content deployment through CI/CD pipelines using GitHub, detection use case implementation, and operational readiness activities.
- Develop and support custom integrations to SIEM platforms, especially Microsoft Sentinel and Google SecOps, including scripts, APIs, parsers, data transformation logic, and data pipeline management activities such as DataBahn.
- Apply AI capabilities in a security-focused manner to improve detection engineering, content optimization, operational efficiency, and analytical outcomes while maintaining strong security and governance awareness.
Requirements
- Hands-on experience with Microsoft Sentinel, Google SecOps, Palo Alto XSIAM, Devo, and Splunk.
- Strong understanding of SIEM architecture, implementation, integration, log management, and threat detection methodologies.
- Experience in developing and tuning security use cases and alerts.
- Proficiency in scripting languages such as Python, PowerShell, and Bash for automation and data processing.
- Experience with cloud platforms including Azure, GCP, and AWS.
- Knowledge of data pipeline tools including Cribl for log routing, enrichment, and deduplication.
- Familiarity with REST APIs, JSON, and integration of third-party security tools.
- Experience with SOAR platforms and playbook development for incident response automation.
- Understanding of security concepts such as cyber-attacks, threat vectors, risk management, and incident management.
- Strong analytical and problem-solving skills with attention to detail.
- Excellent communication, documentation, and client engagement skills.
- Experience deploying SIEM content through CI/CD practices using GitHub, including version control, peer review, change tracking, and structured promotion of content across environments.
- Experience managing security data pipelines and ingestion workflows, including data transformation, normalization, troubleshooting, and platforms or capabilities such as DataBahn.
- Strong understanding of AI concepts and tools, with the ability to apply them in security-oriented use cases such as detection improvement, threat analysis, automation support, and security operations optimization.
- Proficiency in Microsoft Office tools, especially Excel, Word, PowerPoint, Teams, and Outlook, with the ability to create polished client-facing documents, trackers, presentations, and meeting outputs.
- Demonstrated ability to work collaboratively across teams and manage multiple client engagements.
- Commitment to continuous learning and adapting to evolving cybersecurity technologies.
- Experience in a consulting, client delivery, or professional services environment is preferred.
Skills
- Microsoft Sentinel
- Google SecOps
- Palo Alto XSIAM
- Devo
- Splunk
- SIEM
- Python
- PowerShell
- Bash
- Azure
- GCP
- AWS
- Cribl
- REST APIs
- JSON
- SOAR
- CI/CD
- GitHub
- DataBahn
- AI
- Microsoft Office Suite
Location
- Canada
Work Type
- Hybrid
Experience Level
- Senior Associate
- Minimum 3 years of experience in SIEM implementation and security operations
Education Level
- Bachelor's degree in computer science, Cybersecurity, or related field.
- Microsoft Certified: Security Operations Analyst Associate
- SC-200
- AZ-500
- Google Professional Cloud Security Engineer
- CISSP
- CISM
- GIAC
Salary/Compensations
- $84,700 - $134,700
Benefits
- Variable incentive pay programs
- Comprehensive total rewards package
- Inclusive benefits
- Flexibility programs
About the Company
- PwC Canada is committed to cultivating an inclusive, hybrid work environment.
- We’re inspiring and empowering our people to change the world.
- Powered by the latest technology, you’ll be a part of diverse teams helping public and private clients build trust and deliver sustained outcomes.
- This meaningful work, and our continuous development environment, will take your career to the next level.
- We reward your impact, and support your wellbeing, through a competitive compensation package, inclusive benefits and flexibility programs that will help you thrive in work and life.
- PwC Canada acknowledges that we work and live across Turtle Island, on the land that is now known as Canada, which are the lands of the ancestral, treaty and unceded territories of the First Nations, Métis and Inuit Peoples.
- We recognize the systemic racism, colonialism and oppression that Indigenous Peoples have experienced and still go through, and we commit to allyship and solidarity.
Equal Opportunity
- We’re committed to providing accommodation throughout the application, interview, and employment process. If you require accommodation to be at your best, please let us know during the application process.
- The use of artificial intelligence (AI) in recruiting is just getting started, so we know you have questions about how and why we use it.
- At certain points during our recruiting process, we rely on AI to improve your experience.
- This could be during resume review or curating personalized job recommendations, asking you clarifying questions via a chatbot or during our interview scheduling to improve your experience.
- Our use of AI helps ensure we combat bias by evaluating candidates equally and fairly, without seeing identity information, such as your name, or gender for example).
- AI also helps us better predict successful hires by reviewing all applicants for a role and the relationship between your skills, experience and likely success at PwC Canada.
- While AI supports parts of our recruitment process, final hiring decisions always involve human review.
- For more information about our use and protection of your data, please refer to our Privacy Policy (https://www.pwc.com/ca/en/privacy-policy.html).
