05 Aug
|
Nameless
|
Gurugram
Company Overview
Incedo is a US-based consulting, data science and technology services firm with over 3000 people helping clients
from our six offices across US, Mexico and India. We help our clients achieve competitive advantage through
end-to-end digital transformation. Our uniqueness lies in bringing together strong engineering, data science, and
design capabilities coupled with deep domain understanding. We combine services and products to maximize
business impact for our clients in telecom, Banking, Wealth Management, product engineering and life science
& healthcare industries.
Working at Incedo will provide you an prospect to work with industry leading client organizations, deep
technology and domain experts, and global teams. Incedo University, our learning platform, provides ample
learning opportunities starting with a structured onboarding program and carrying throughout various stages of
your career. A variety of fun activities is also an integral part of our friendly work environment. Our flexible
career paths allow you to grow into a program manager, a technical architect or a domain expert based on your
skills and interests.
Our Mission is to enable our clients to maximize business impact from technology by
- Harnessing the transformational impact of emerging technologies
- Bridging the gap between business and technology
Role Description
Job Description
The Senior SIEM Engineer will be responsible for engineering, optimizing, and maintaining the organization's Security Information and Event Management (SIEM) platform within a Managed Security Services (MSSP) environment. The role requires strong expertise in log management, security event correlation, detection engineering, platform administration, and performance optimization to ensure a highly available and effective security monitoring capability.
The engineer will work closely with SOC Analysts, Security Architects, Infrastructure Teams, and Technology Vendors to continuously improve threat detection capabilities, platform stability, and operational efficiency.
Role and Responsibilities
Key Responsibilities
• SIEM Platform Engineering
- Design, develop, and maintain custom log parsers and normalization logic for supported log sources.
- Configure and maintain custom event properties, field extraction, and data normalization.
- Ensure accurate parsing and categorization of security events across all onboarded technologies.
- Perform log source onboarding, validation, troubleshooting, and lifecycle management.
- Improve log quality to maximize detection accuracy and visibility.
• Detection Engineering & Content Optimization
- Develop,
review, and continuously optimize correlation rules and detection use cases.
- Reduce false positives and improve the overall Signal-to-Noise Ratio (SNR).
- Develop custom searches, dashboards, reports, and threat hunting queries.
- Support MITRE ATT&CK; aligned detection use cases.
- Enhance SOC detection capability through continuous content improvement.
• Platform Health & Performance Management
- Perform proactive health monitoring of the SIEM platform and associated components.
- Monitor event processing pipelines, indexing performance, storage utilization, CPU, memory, and database health.
- Identify and resolve performance bottlenecks before they impact security operations.
- Support platform upgrades, patching, backup, disaster recovery, and capacity planning.
• Log Source Integration & Data Engineering
- Integrate and troubleshoot security technologies including firewalls, IDS/IPS, endpoint security, cloud platforms, operating systems, applications, identity platforms, and network devices.
- Configure and validate industry-standard log formats such as Syslog, CEF, LEEF, JSON, XML, and custom log formats.
- Ensure reliable log collection, parsing, and event normalization across all supported technologies.
• Operational Support & Incident Resolution
- Provide advanced engineering support for SIEM platform issues.
- Support critical production incidents and participate in major incident bridge calls.
- Coordinate with OEMs and third-party vendors for platform-related issues.
- Perform emergency troubleshooting, maintenance, and change implementation outside business hours whenever required.
• Continuous Service Improvement
- Drive continuous improvements in platform performance, scalability, and stability.
- Automate repetitive engineering tasks wherever possible.
- Develop technical documentation, SOPs, engineering standards, and operational runbooks.
- Recommend enhancements to improve detection coverage and SOC operational efficiency.
Technical Skills
Nice-to-have skills
Preferred Skills
- Experience with one or more enterprise SIEM platforms.
- Experience with scripting languages such as Python, PowerShell, or Shell.
- Knowledge of REST APIs and automation frameworks.
- Experience with SOAR integrations.
- Familiarity with cloud security platforms (AWS, Azure, OCI, GCP).
- Knowledge of Threat Intelligence Platforms and Detection Engineering best practices.
- Understanding of DevSecOps and Infrastructure as Code (IaC).
Personal Attributes
- Strong ownership and accountability.
- Excellent analytical and troubleshooting abilities.
- Ability to work independently under pressure.
- Strong customer focus with a proactive approach to problem-solving.
- Continuous learning mindset and passion for cyber security.
- Ability to manage multiple priorities in a fast-paced 24×7 operational environment.
Qualifications
Qualifications and Experience
• Experience
- 5–8 years of experience in Cyber Security with a minimum of 4 years in SIEM Engineering or Security Platform Engineering.
- Experience working in Enterprise SOC or MSSP environments supporting 24×7 operations.
- Hands-on experience in log management, parser development, detection engineering, and SIEM administration.
- Experience supporting complex production environments with multiple security technologies.
• Technical Skills
- Strong understanding of Security Information and Event Management (SIEM) concepts.
- Experience in log source onboarding, parsing, normalization, and event correlation.
- Experience in detection rule development, tuning, and optimization.
- Knowledge of threat detection methodologies and MITRE ATT&CK; Framework.
- Experience in search query optimization, dashboard development, and reporting.
- Strong understanding of networking concepts, TCP/IP, DNS, HTTP/HTTPS, Syslog, authentication protocols, and security event logging.
- Knowledge of Windows, Linux, Active Directory, Cloud Security, Firewalls, IDS/IPS, Endpoint Security, Proxy Solutions, Identity Platforms, and Security Monitoring technologies.
• Communication & Leadership
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent stakeholder management and client-facing communication skills.
- Ability to lead technical discussions and coordinate cross-functional teams during major incidents.
- Strong documentation, reporting, and presentation skills.
• Certifications
Preferred certifications include one or more of the following:
- GIAC, CISSP, GCIH, GCIA, Security+, CySA+, or equivalent Security/SIEM certifications.
Vendor-specific SIEM certifications are an added advantage
Company Value
We value diversity at Incedo. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
📌 Security-Engineer (Gurugram)
🏢 Nameless
📍 Gurugram