15 Aug
|
Tata Consultancy Services
|
Indore
15 Aug
Tata Consultancy Services
Indore
Role : SIEM Consultant
Exp Range: 5 to 8 Years
Location: Indore
Must Have
- experience in SOC, Threat Detection, Incident Response, or SIEM Engineering roles.
- Solid hands-on expertise with Microsoft Sentinel, including KQL, analytics rules, threat hunting, and playbooks.
- Experience working with at least one additional SIEM platform, such as Splunk, QRadar, or Elastic.
- Solid understanding of MITRE ATT&CK;, detection engineering, and log analysis.
- Proficiency in PowerShell and/or Python scripting for automation.
- Familiarity with EDR, IAM, firewall, and cloud security logs.
- Must have experience implementing and deploying SIEM solutions.
Responsibilities
- Onboard and normalize log sources across cloud, endpoint,
network, and SaaS environments.
- Develop, optimize, and tune detection rules using KQL, aligned with the MITRE ATT&CK; framework.
- Create dashboards, health checks, reports, and key performance indicators (KPIs).
- Implement and maintain SOAR automation using Microsoft Sentinel Playbooks and Logic Apps.
- Support threat hunting activities and assist with incident investigation and response.
- Ensure SIEM platform performance, cost optimization, and compliance requirements are met.
📌 Siem Administrator (Indore)
🏢 Tata Consultancy Services
📍 Indore