02 Sep
|
Happiest Minds Technologies
|
Bengaluru
02 Sep
Happiest Minds Technologies
Bengaluru
- SOC L3 Engineer (Elastic SIEM & SOAR)
Location: Bengaluru / India
Experience: 6-10+ Years
Role: SOC L3 / Senior Security Operations Engineer
Role Summary
Seeking an experienced SOC L3 skilled with strong expertise in Elastic Security (SIEM) and SOAR platforms. The candidate should possess hands-on experience in SIEM implementation, administration, content engineering, threat hunting, incident response, and SOC optimization across multiple SIEM technologies such as Microsoft Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic, or similar platforms.
Key Responsibilities
Lead L3 investigations for complex security incidents and advanced threats.
Design, implement, and optimize Elastic SIEM and Elastic Security deployments.
Develop and maintain SOAR playbooks, automation workflows, and integrations.
Build and tune detection rules, correlation logic, dashboards, alerts, and threat hunting content.
Support end-to-end SIEM implementation including onboarding log sources, parsing, normalization, and data pipelines.
Perform threat hunting, malware analysis, and root cause investigations.
Provide technical guidance to L1/L2 analysts and lead incident response activities.
Integrate threat intelligence feeds and improve detection maturity.
Conduct use case development, validation, and security monitoring enhancements.
Participate in SOC transformation, SIEM migrations, and platform evaluations.
Required Technical Skills
Robust hands-on experience with Elastic SIEM / Elastic Security.
Experience with Elastic Defend, Kibana, Elasticsearch, Logstash, Beats, Fleet, and detection engineering.
Hands-on experience in SOAR implementation and automation orchestration.
Experience implementing or managing other SIEM platforms such as Microsoft Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic, Stellar Cyber, or equivalent.
Robust understanding of Windows, Linux, Active Directory, Azure, AWS, networking, and cloud security.
Knowledge of MITRE ATT&CK;, Cyber Kill Chain, IOC analysis, and threat intelligence.
Experience with scripting (Python, PowerShell, Bash) for automation.
Understanding of EDR/XDR, NDR, Email Security, IAM, and Security Controls integration.
Preferred Certifications
Elastic Certified Engineer, Microsoft SC-200, AZ-500, Splunk, QRadar, GCIH, GCIA, CEH, CISSP, or equivalent certifications.
Soft Skills
Strong analytical and troubleshooting skills, stakeholder communication, client-facing experience, documentation skills, mentoring capability, and ability to lead critical security incidents.
📌 TECHNICAL LEAD - Elastic Search (Bengaluru)
🏢 Happiest Minds Technologies
📍 Bengaluru