At Broadridge, we've built a culture where the highest goal is to empower others to accomplish more. If you’re passionate about developing your career, while helping others along the way, come join the Broadridge team.
We are seeking a Microsoft Sentinel SIEM Engineer with strong experience designing, operating, and scaling enterprise Microsoft Sentinel SIEM or other SIEM platforms to support 24x7 Security Operations. This role is responsible for platform health, log ingestion pipelines, normalization, enrichment, detection content support, and integrations with security and IT systems. The SOC Engineer will partner closely with SOC Analysts, Threat Intelligence, BISG Information Security teams, and other stakeholders to ensure high-quality security telemetry, reliable detections, and an optimized analyst experience. This role also supports Mergers & Acquisitions (M&A) by onboarding new log sources and environments into the enterprise SIEM.
Key Responsibilities
1. Engineer, operate, and optimize Microsoft Sentinel across one or more Log Analytics workspaces
2. Ensure Sentinel reliability, scalability, performance, and cost efficiency
3. Manage workspace architecture, retention, daily cap, and data tiering strategies
4. Monitor Sentinel platform health, ingestion latency, connector failures, and query performance
5. Design, build, and maintain scalable, highly available log ingestion pipelines, including parsing, normalization, enrichment, and filtering using technologies like Syslog, Sentinel data connectors, Azure Monitor Agents, etc.
6. Onboard and maintain data sources across cloud, on-prem, SaaS, and security tools (EDR, IAM, network, application logs)
7. Tune data quality, performance, and cost efficiency across the SIEM environment
8. Develop and maintain integrations between the SIEM and security platforms (EDR, SOAR, Threat Intel, ITSM)
9. Support M&A security onboarding by integrating acquired environments into the SIEM
10. Implement monitoring, alerting, and health checks for SIEM infrastructure and data pipelines
11. Troubleshoot ingestion, parsing, correlation, and performance issues impacting SOC visibility
12. Automate repetitive SIEM operational tasks using scripting or platform-native capabilities
13. Document SIEM architecture, data sources, standards, and operational runbooks
14. Collaborate with cloud, infrastructure, and network teams to ensure complete and reliable telemetry coverage
Required Skills & Qualifications
15. 5+ years of experience in SIEM Engineering, Security Operations Engineering, or SOC Platform roles
16. Strong hands-on experience with at least one enterprise SIEM platform (e.g., Splunk, Azure Sentinel, Elastic, QRadar) - preference to candidates with MS Sentinel experience.
17. Deep understanding of log formats, schemas, parsing, normalization, and enrichment techniques
18. Experience onboarding diverse log sources: cloud platforms, operating systems, applications, IAM, and security tools
19. Strong troubleshooting skills for ingestion latency, parsing errors, dropped events, and performance bottlenecks
20. Understanding of detection concepts, correlation logic, and SOC workflows
21. Experience integrating SIEM with SOAR, EDR, ITSM, and threat intelligence platforms
22. Familiarity with cloud environments (AWS and/or Azure) and cloud-native logging services
23. Scripting experience (Python, SPL, KQL, or equivalent) to support automation and analysis
24. Solid foundation in networking, authentication, and security fundamentals
Preferred Qualifications
25. Background in SIEM deployments or management
26. Experience optimizing SIEM performance, scalability, and cost management
27. Experience supporting SIEM use cases during M&A integrations
28. Hands-on experience with SOAR and automated response workflows
29. Familiarity with Infrastructure as Code or configuration management for SIEM infrastructure
30. Experience working in regulated or financial services environments
Soft Skills
31. Strong problem-solving and troubleshooting skills
32. Ability to work across Security, IT, and Engineering teams
33. Strong documentation and communication skills
34. Automation-first and reliability-focused mindset
Hybrid Flexible at Broadridge
We are made up of high-performing teams that meet in person to learn and collaborate as needed. This role is considered hybrid, which means you’ll be assigned to a Broadridge office.
#LI-Hybrid
#LI-LM1
We are dedicated to fostering a collaborative, engaging, and inclusive environment and are committed to providing a workplace that empowers associates to be authentic and bring their best to work. We believe that associates do their best when they feel safe, understood, and valued, and we work diligently and collaboratively to ensure Broadridge is a company—and ultimately a community—that recognizes and celebrates everyone’s unique perspective.
Use of AI in Hiring
As part of the recruiting process, Broadridge may use technology, including artificial intelligence (AI)-based tools, to help review and evaluate applications. These tools are used only to support our recruiters and hiring managers, and all employment decisions include human review to ensure fairness, accuracy, and compliance with applicable laws. Please note that honesty and transparency are critical to our hiring process. Any attempt to falsify, misrepresent, or disguise information in an application, resume, assessment, or interview will result in disqualification from consideration.