Kolkata, West Bengal, India
Onsite
Line of Service
AdvisoryIndustry/Sector
Not ApplicableSpecialism
MicrosoftManagement Level
Senior AssociateJob Description & Summary
At PwC, our people in business application consulting specialise in consulting services for a variety of business applications, helping clients optimise operational efficiency. These individuals analyse client needs, implement software solutions, and provide training and support for seamless integration and utilisation of business applications, enabling clients to achieve their strategic objectives.*Why PWC
At PwC, you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities. This purpose-led and values-driven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world. We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life. Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other. Learn more about us.
At PwC, we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregnancy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law. We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm’s growth. To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations.
job Description & summary:
We’re looking for an early-career SIEM Engineer to join our Global SIEM team and help drive the next phase of our security analytics and observability journey. You will be hands-on with Splunk (Enterprise/Cloud/ES) and Cribl (Stream/Edge) to onboard, normalize, and optimize security data, while building/maintaining detections, dashboards, and automations that support our SOC, Threat Hunting, and Incident Response teams.
You’ll thrive here if you enjoy crafting robust data pipelines, writing efficient SPL, applying security frameworks (MITRE ATT&CK, NIST), and continuously improving signal quality and time-to-detect/resolve.
Onboard new log sources (network, endpoint, identity, cloud, SaaS) into Splunk via Cribl (Stream/Edge), ensuring secure, reliable, and cost-optimized ingestion.
Detection, Content & Operations
Security Mindset & Collaboration
Required Qualifications
Preferred Certifications (one or more)
Equivalent or higher-level credentials are welcome.
Splunk
Cribl
Security
Nice-to-Have Skills
Success Metrics (What Good Looks Like)
Mandatory skill sets:
Platform & Data Engineering • Onboard new log sources (network, endpoint, identity, cloud, SaaS) into Splunk via Cribl (Stream/Edge), ensuring secure, reliable, and cost-optimized ingestion. • Build and manage Cribl pipelines (parsing, shaping, routing, redaction, filtering, sampling) aligned to data retention and ingest budgets. • Implement and maintain Splunk data models, CIM mappings, sourcetypes, index strategies, HEC tokens, and ingestion best practices. • Monitor and optimize search performance (SPL tuning, data model acceleration, summary indexing, KV stores, lookup strategies).
Preferred skill sets:•
Develop, tune, and maintain correlation searches and detections in Splunk Enterprise Security (including Risk-Based Alerting). • Build operational and executive dashboards, reports, and analytics for SOC and leadership stakeholders. • Maintain runbooks, field extractions (regex), data quality checks, and use case documentation.
Years of experience required
:2 to 5 Years
Education Qualification:
B.E. / B.Tech / MBA. All qualifications should be in regular full-time mode with no extension of course duration due to backlogs • Splunk Core Certified Power User • Splunk Core Certified Admin • Splunk Enterprise Security Certified Admin (nice to have) • Splunk Cloud Admin (nice to have) Cribl Certified Observability Engineer (CCOE) – Stream • Cribl Certified Observability Engineer – Edge (nice to have)
Education (if blank, degree and/or field of study not specified)
Degrees/Field of Study required: Bachelor of Engineering, Master of Business AdministrationDegrees/Field of Study preferred:Certifications (if blank, certifications not specified)
Required Skills
SIEM ToolsOptional Skills
Accepting Feedback, Accepting Feedback, Active Listening, Analytical Reasoning, Analytical Thinking, Application Software, Business Data Analytics, Business Management, Business Technology, Business Transformation, Communication, Creativity, Documentation Development, Embracing Change, Emotional Regulation, Empathy, Implementation Research, Implementation Support, Implementing Technology, Inclusion, Intellectual Curiosity, Learning Agility, Optimism, Performance Assessment, Performance Management Software {+ 16 more}Desired Languages (If blank, desired languages not specified)
Travel Requirements
Not SpecifiedAvailable for Work Visa Sponsorship?
NoGovernment Clearance Required?
NoJob Posting End Date
April 14, 2026Want to know if this job is worth applying to?