SIEM Content Developer (Pune)

SIEM Content Developer (Pune)

28 Aug
|
Persistent Systems
|
Pune

28 Aug

Persistent Systems

Pune

Job Type: Full-time

Remote: Hybrid

About Position:The SIEM Content Developer Splunk is a critical role within our Global Security Operations Center (SOC). This position is responsible for designing, developing, tuning, and maintaining Splunk detection content to enhance threat detection, incident response, and security monitoring across enterprise environments. The ideal candidate will collaborate closely with SOC analysts, threat hunters, incident response teams, and security architects to ensure the delivery of high-fidelity alerts with minimal false positives, all while aligning with the MITRE ATT&CK; framework.Role: SIEM Content Developer – SplunkLocation: PuneExperience: Between 8 to 12 YearsJob Type: Full Time EmploymentWhat You'll Do:SIEM Content EngineeringDesign, develop, and maintain Splunk correlation searches, alerts, and dashboards.Build use-case driven detections aligned to MITRE ATT&CK; techniques.Develop SPL queries for complex detection logic across diverse log sources.Create risk-based alerting (RBA) and notable events.Maintain version-controlled SIEM content lifecycle (development, testing, production). Detection Use Case DevelopmentTranslate threat scenarios, attack paths, and TTPs into Splunk detections.Develop detections for various environments including Endpoint (EDR, Windows, Linux, macOS), Network (Firewall, IDS/IPS, Proxy, VPN), Cloud (AWS, Azure, GCP security logs), Identity (AD, Azure AD, Okta), and Application & Database logs.Map detections to MITRE techniques, severity, and response actions.Tuning & OptimizationPerform alert tuning and false-positive reduction.



Optimize SPL queries for performance and scalability.Improve signal-to-noise ratio through context enrichment and suppression logic. SOC & IR Enablement Work with SOC L1/L2/L3 teams to refine alert logic.Create runbooks and investigation guidance for each detection.Support incident response and threat hunting activities.Assist with Purple Team exercises and detection gap analysis. Documentation & GovernanceMaintain use case documentation, data source dependencies, and logic flows.Support audits and compliance reporting where SIEM evidence is required.Track coverage metrics (ATT&CK; coverage, detection maturity).Expertise You'll Bring:Solid hands-on experience with Splunk Enterprise / Splunk ES.Advanced proficiency in SPL (Search Processing Language).Experience building correlation searches, notables, dashboards, and RBA.Solid understanding of SOC operations and incident response workflows.Strong knowledge of the MITRE ATT&CK; framework.Log Source Experience: Endpoint (CrowdStrike, Defender, Carbon Black), Network (Palo Alto, Cisco, Fortinet, Zscaler), Cloud (AWS CloudTrail, Azure Activity Logs, GCP logs), Identity (Active Directory, Azure AD, Okta), Email & SaaS (Proofpoint, O365, Google Workspace).Experience with SOAR integration (Splunk SOAR, Palo Alto XSOAR).Threat hunting and Purple Team collaboration.Experience with content migration from other SIEMs (QRadar, Sentinel, ArcSight).Knowledge of data onboarding, CIM normalization,



and TA configuration.Certifications (Preferred) Splunk Enterprise Security Certified Admin.Splunk Core Power User / Admin.GIAC GCED / GCIA / GCIH.MITRE ATT&CK; Defender (MAD).Educational background: Bachelor's degree in a relevant discipline or equivalent practical experience.Benefits:Competitive salary and benefits packageCulture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certificationsOpportunity to work with cutting-edge technologiesEmployee engagement initiatives such as project parties, flexible work hours, and Long Service awardsAnnual health check-upsInsurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parentsValues-Driven, People-Centric & Inclusive Work Environment:Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.We support hybrid work and flexible hours to fit diverse lifestyles.Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employmentLet’s unleash your full potential at Persistent - persistent.com/careers“Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.”

📌 SIEM Content Developer (Pune)
🏢 Persistent Systems
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: siem content developer (pune) / pune