23 Aug
|
Tata Consultancy Services
|
Bengaluru
23 Aug
Tata Consultancy Services
Bengaluru
Skill: SIEM Splunk
Experience: 5+years
Date of Interview: 29th August 2026
Interview location: Kolkata, Bangalore
Mode of Interview: In Person(Face-to-Face)
Job Description:
Role Purpose
The SIEM Engineer (L2) is responsible for advanced administration, engineering, and optimization of SIEM platforms (Splunk, Sentinel).This role ensures robust security event monitoring, incident analysis, and continuous improvement of detection capabilities, supporting regulatory compliance and audit readiness.
Key Responsibilities
SIEM Operations & Engineering
- Prepare and maintain runbooks for all configured alerts in Splunk and Sentinel.
- Conduct health checks of SIEM components (Splunk: heavy forwarders, indexers, search heads, master node, deployment server; Sentinel: all relevant components).
- Configuration of use cases in terms of alerts, reports or dashboard as per requirement
- Deploying Splunk Enterprise / Cloud, indexers, search needs, forwarders
- Managing clusters, licensing,
scaling and performance optimization
- Perform upgrades, migrations and patching (e.g. OS upgrades, Spunk version updates)
- Configure indexes, source types, and parsing rules (Props.conf, transforms.conf)
- Investigate ingestion issues, parsing errors and search performance problems
- Monitor uptime and health status of SIEM tools and log collectors.
- Review and optimize monitoring rules against industry standards (MITRE, Kill Chain frameworks).
- Collect requirements, develop, test, and deploy new use cases in Splunk and Sentinel.
- Integrate current devices into SIEM platforms and troubleshoot integration issues.
- Follow change management processes for implementing and deploying use cases.
- Define and follow procedures for integrating new devices to SIEM tools.
- Review deliverables and ensure timely completion as per defined frequency.
📌 SIEM Splunk (Bengaluru)
🏢 Tata Consultancy Services
📍 Bengaluru