We use cookies for the best user experience on our website, including to personalize content & offerings, to provide social media features and to analyze traffic. By clicking “Accept All Cookies” you agree to our use of cookies. You can also manage your cookies by clicking on the "Cookie Preferences" and selecting the categories you would like to accept. For more information on how we use cookies please visit our and Modify Cookie Preferences
Reject All Cookies Accept All Cookies
Track Lead - Security Investigations, SIEM
India
Job Description
Track Lead - Security Investigations, SIEM
Noida, Uttar Pradesh
Job Summary
Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.
Key Responsibilities
Conduct hypothesis-based and IOC-driven threat hunting across: o Endpoint (EDR/XDR) o SIEM / Log Management platforms o Network telemetry (NDR) o Identity logs (AD / Entra ID) o Cloud platforms (Azure, AWS, M365) • Identify stealthy and advanced threats, including: o Living off the Land (LotL) techniques o Advanced Persistent Threats (APTs) o Lateral movement and privilege escalation o Insider threat indicators • Develop and execute MITRE ATT&CK;-aligned hunting hypotheses • Convert hunting findings into: o Security incidents o New detection rules (SIEM / EDR / XDR) o Change or service requests (misconfigurations, logging gaps) • Collaborate with SOC, Incident Response, and Threat Intelligence teams • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated)
Skill Requirements
Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM) • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex) • Proficiency in KQL / SPL / advanced hunting queries • Deep understanding of MITRE ATT&CK; techniques and TTPs • Strong OS knowledge: Windows, Linux, macOS • Basic scripting skills (PowerShell / Python preferred) • Cloud security exposure (Azure, AWS, M365 Defender) Experience & Soft Skills • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting • Strong analytical and investigative mindset • Client facing reporting and presentation skills • Willingness to work in 24×7 SOC environments
Other Requirements
Role Overview Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.
Key Responsibilities • Conduct hypothesis-based and IOC-driven threat hunting across: o Endpoint (EDR/XDR) o SIEM / Log Management platforms o Network telemetry (NDR) o Identity logs (AD / Entra ID) o Cloud platforms (Azure, AWS, M365) • Identify stealthy and advanced threats, including: o Living off the Land (LotL) techniques o Advanced Persistent Threats (APTs) o Lateral movement and privilege escalation o Insider threat indicators • Develop and execute MITRE ATT&CK;-aligned hunting hypotheses • Convert hunting findings into: o Security incidents o New detection rules (SIEM / EDR / XDR) o Change or service requests (misconfigurations, logging gaps) • Collaborate with SOC, Incident Response, and Threat Intelligence teams • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated) Technical Skills • Solid expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM) • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex) • Proficiency in KQL / SPL / advanced hunting queries • Deep understanding of MITRE ATT&CK; techniques and TTPs • Strong OS knowledge: Windows, Linux, macOS • Basic scripting skills (PowerShell / Python preferred) • Cloud security exposure (Azure, AWS, M365 Defender) Experience & Soft Skills • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting • Strong analytical and investigative mindset • Client facing reporting and presentation skills • Willingness to work in 24×7 SOC environments
Information at a Glance
Why HCLTech?
At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.
HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.
Copyright © 2026 HCL Technologies Limited
×
Cookie Consent Manager
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. Because we respect your right to privacy,
you can choose not to allow some types of cookies. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
Required Cookies
These cookies are required to use this website and can't be turned off.
Required Cookies
Show More Details
Required Cookies Provider Description Enabled
SAP as service provider
We use the following session cookies, which are all required to enable the website to function:
- "route" is used for session stickiness
- "careerSiteCompanyId" is used to send the request to the correct data center
- "JSESSIONID" is placed on the visitor's device during the session so the server can identify the visitor
- "Load balancer cookie" (actual cookie name may vary) prevents a visitor from bouncing from one instance to another
Cookies from provider SAPasserviceprovider are required and cannot be turned off
Functional Cookies
These cookies provide a better customer experience on this site, such as by remembering your login details, optimizing video performance, or providing us with information about how our site is used. You may freely choose to accept or decline these cookies at any time. Note that certain functionalities that these third-parties make available may be impacted if you do not accept these cookies.
Consent to all Functional Cookies
Show More Details
Functional Cookies Provider Description Enabled
Vimeo
Vimeo is a video hosting, sharing, and services platform focused on the delivery of video. Opting out of Vimeo cookies will disable your ability to watch or interact with Vimeo videos.
Consent to cookies from provider Vimeo
YouTube
YouTube is a video-sharing service where users can create their own profile, upload videos, watch, like, and comment on videos. Opting out of YouTube cookies will disable your ability to watch or interact with YouTube videos.
Consent to cookies from provider YouTube
Advertising Cookies
These cookies serve ads that are relevant to your interests. You may freely choose to accept or decline these cookies at any time. Note that certain functionality that these third parties make available may be impacted if you do not accept these cookies.
Consent to all Advertising Cookies
Show More Details
Advertising Cookies Provider Description Enabled
Google Analytics
Google Analytics is a web analytics service offered by Google that tracks and reports website traffic.
Consent to cookies from provider GoogleAnalytics
Google Tag Manager
Google Tag Manager is a tag management system for conversion tracking, site analytics, remarketing, and more.
Consent to cookies from provider GoogleTagManager
LinkedIn
LinkedIn is an employment-oriented social networking service. We use the Apply with LinkedIn feature to allow you to apply for jobs using your LinkedIn profile. Opting out of LinkedIn cookies will disable your ability to use Apply with LinkedIn.
📌 Track Lead - Security Investigations, SIEM (India)
🏢 HCLTech
📍 India