Siem Content Developer (India)

Siem Content Developer (India)

29 Aug
|
Persistent Systems
|
India

29 Aug

Persistent Systems

India

About Position:

The SIEM Content Developer Splunk is a critical role within our Global Security Operations Center (SOC). This position is responsible for designing, developing, tuning, and maintaining Splunk detection content to enhance threat detection, incident response, and security monitoring across enterprise environments. The ideal candidate will collaborate closely with SOC analysts, threat hunters, incident response teams, and security architects to ensure the delivery of high-fidelity alerts with minimal false positives, all while aligning with the MITRE ATT&CK; framework.
- Role: SIEM Content Developer – Splunk
- Location: Pune
- Experience: Between 8 to 12 Years
- Job Type: Full Time Employment

What You'll Do:
- SIEM Content Engineering
- Design, develop, and maintain Splunk correlation searches, alerts, and dashboards.
- Build use-case driven detections aligned to MITRE ATT&CK; techniques.
- Develop SPL queries for complex detection logic across diverse log sources.
- Create risk-based alerting (RBA) and notable events.




- Maintain version-controlled SIEM content lifecycle (development, testing, production). Detection Use Case Development
- Translate threat scenarios, attack paths, and TTPs into Splunk detections.
- Develop detections for various environments including Endpoint (EDR, Windows, Linux, macOS), Network (Firewall, IDS/IPS, Proxy, VPN), Cloud (AWS, Azure, GCP security logs), Identity (AD, Azure AD, Okta), and Application & Database logs.
- Map detections to MITRE techniques, severity, and response actions.
- Tuning & Optimization
- Perform alert tuning and false-positive reduction. Optimize SPL queries for performance and scalability.
- Improve signal-to-noise ratio through context enrichment and suppression logic. SOC & IR Enablement Work with SOC L1/L2/L3 teams to refine alert logic.
- Create runbooks and investigation guidance for each detection.
- Support incident response and threat hunting activities.
- Assist with Purple Team exercises a

📌 Siem Content Developer (India)
🏢 Persistent Systems
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: siem content developer (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: siem content developer (india) / india