Track Lead - Security Investigations, SIEM (India)

Track Lead - Security Investigations, SIEM (India)

31 Aug
|
HCLTech
|
India

31 Aug

HCLTech

India

We use cookies for the best user experience on our website, including to personalize content & offerings, to provide social media features and to analyze traffic. By clicking “Accept All Cookies” you agree to our use of cookies. You can also manage your cookies by clicking on the "Cookie Preferences" and selecting the categories you would like to accept. For more information on how we use cookies please visit our and Modify Cookie Preferences

Reject All Cookies Accept All Cookies

Track Lead - Security Investigations, SIEM

India

Job Description

Track Lead - Security Investigations, SIEM

Noida, Uttar Pradesh

Job Summary

Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.

Key Responsibilities

Conduct hypothesis-based and IOC-driven threat hunting across: o Endpoint (EDR/XDR) o SIEM / Log Management platforms o Network telemetry (NDR) o Identity logs (AD / Entra ID) o Cloud platforms (Azure, AWS, M365) • Identify stealthy and advanced threats, including: o Living off the Land (LotL) techniques o Advanced Persistent Threats (APTs) o Lateral movement and privilege escalation o Insider threat indicators • Develop and execute MITRE ATT&CK;-aligned hunting hypotheses • Convert hunting findings into: o Security incidents o New detection rules (SIEM / EDR / XDR) o Change or service requests (misconfigurations, logging gaps) • Collaborate with SOC, Incident Response, and Threat Intelligence teams • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated)

Skill Requirements

Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM) • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex) • Proficiency in KQL / SPL / advanced hunting queries • Deep understanding of MITRE ATT&CK; techniques and TTPs • Strong OS knowledge: Windows, Linux, macOS • Basic scripting skills (PowerShell / Python preferred) • Cloud security exposure (Azure, AWS, M365 Defender) Experience & Soft Skills • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting • Strong analytical and investigative mindset • Client facing reporting and presentation skills • Willingness to work in 24×7 SOC environments

Other Requirements

Role Overview Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.



Key Responsibilities • Conduct hypothesis-based and IOC-driven threat hunting across: o Endpoint (EDR/XDR) o SIEM / Log Management platforms o Network telemetry (NDR) o Identity logs (AD / Entra ID) o Cloud platforms (Azure, AWS, M365) • Identify stealthy and advanced threats, including: o Living off the Land (LotL) techniques o Advanced Persistent Threats (APTs) o Lateral movement and privilege escalation o Insider threat indicators • Develop and execute MITRE ATT&CK;-aligned hunting hypotheses • Convert hunting findings into: o Security incidents o New detection rules (SIEM / EDR / XDR) o Change or service requests (misconfigurations, logging gaps) • Collaborate with SOC, Incident Response, and Threat Intelligence teams • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated) Technical Skills • Solid expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM) • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex) • Proficiency in KQL / SPL / advanced hunting queries • Deep understanding of MITRE ATT&CK; techniques and TTPs • Strong OS knowledge: Windows, Linux, macOS • Basic scripting skills (PowerShell / Python preferred) • Cloud security exposure (Azure, AWS, M365 Defender) Experience & Soft Skills • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting • Strong analytical and investigative mindset • Client facing reporting and presentation skills • Willingness to work in 24×7 SOC environments

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.

Copyright © 2026 HCL Technologies Limited

×

Cookie Consent Manager

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. Because we respect your right to privacy,



you can choose not to allow some types of cookies. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Required Cookies

These cookies are required to use this website and can't be turned off.

Required Cookies

Show More Details

Required Cookies Provider Description Enabled
SAP as service provider

We use the following session cookies, which are all required to enable the website to function:

- "route" is used for session stickiness
- "careerSiteCompanyId" is used to send the request to the correct data center
- "JSESSIONID" is placed on the visitor's device during the session so the server can identify the visitor
- "Load balancer cookie" (actual cookie name may vary) prevents a visitor from bouncing from one instance to another

Cookies from provider SAPasserviceprovider are required and cannot be turned off

Functional Cookies

These cookies provide a better customer experience on this site, such as by remembering your login details, optimizing video performance, or providing us with information about how our site is used. You may freely choose to accept or decline these cookies at any time. Note that certain functionalities that these third-parties make available may be impacted if you do not accept these cookies.

Consent to all Functional Cookies

Show More Details

Functional Cookies Provider Description Enabled
Vimeo

Vimeo is a video hosting, sharing, and services platform focused on the delivery of video. Opting out of Vimeo cookies will disable your ability to watch or interact with Vimeo videos.

Consent to cookies from provider Vimeo

YouTube

YouTube is a video-sharing service where users can create their own profile, upload videos, watch, like, and comment on videos. Opting out of YouTube cookies will disable your ability to watch or interact with YouTube videos.

Consent to cookies from provider YouTube

Advertising Cookies

These cookies serve ads that are relevant to your interests. You may freely choose to accept or decline these cookies at any time. Note that certain functionality that these third parties make available may be impacted if you do not accept these cookies.

Consent to all Advertising Cookies

Show More Details

Advertising Cookies Provider Description Enabled
Google Analytics

Google Analytics is a web analytics service offered by Google that tracks and reports website traffic.

Consent to cookies from provider GoogleAnalytics

Google Tag Manager

Google Tag Manager is a tag management system for conversion tracking, site analytics, remarketing, and more.

Consent to cookies from provider GoogleTagManager

LinkedIn

LinkedIn is an employment-oriented social networking service. We use the Apply with LinkedIn feature to allow you to apply for jobs using your LinkedIn profile. Opting out of LinkedIn cookies will disable your ability to use Apply with LinkedIn.

📌 Track Lead - Security Investigations, SIEM (India)
🏢 HCLTech
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: track lead - security investigations, siem (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: track lead - security investigations, siem (india) / india