06 Sep
|
HALA INFOSEC
|
Hyderabad
06 Sep
HALA INFOSEC
Hyderabad
Company Description Hala Infosec is a fast-growing cybersecurity firm dedicated to delivering quality-driven, outcome-focused security services across SOC-as-a-Service, security engineering, OT security, GRC, security deployments, and testing.. Hala Infosec emphasizes innovation, adaptability, and client success, helping organizations operate securely in an evolving threat landscape. The team culture is diverse and collaborative, combining emerging talent, subject matter experts, and seasoned leaders in a learning-focused, empowering environment.
Integrity, transparency, and business-aligned security outcomes guide how Hala Infosec supports both its clients and its professionals.
Role Description:
We are looking for an experienced SIEM Engineer to join our Security Operations team. The ideal candidate will have hands-on experience in SIEM engineering, log management, detection engineering, and security monitoring, with solid expertise in Palo Alto Cortex XSIAM and Splunk.
The candidate will be responsible for designing, implementing, maintaining, and optimizing SIEM platforms, onboarding and troubleshooting security data sources, developing detection use cases, and supporting the SOC in improving its overall detection and response capabilities.
- Develop, implement, and tune SIEM correlation rules, detection rules, alerts, and use cases.
- Create and optimize Splunk SPL / XQL queries, dashboards, reports, alerts, and correlation searches.
- Work with Cortex XSIAM/XDR for data ingestion, detection, investigation,
and security analytics.
- Perform log parsing, normalization, field extraction, and data quality troubleshooting.
- Monitor SIEM data ingestion and troubleshoot issues related to missing, delayed, duplicated, or incorrectly parsed logs.
- Develop and maintain SOC detection use cases aligned with MITRE ATT&CK; and emerging threats.
- Perform alert tuning and false-positive reduction while maintaining effective detection coverage.
- Support threat hunting activities by developing advanced queries and analytics.
- Work closely with SOC analysts, threat hunters, incident responders, and infrastructure teams to improve detection and response capabilities.
- Develop and maintain SIEM dashboards, operational reports, and security metrics.
- Participate in SIEM platform upgrades, migrations, integrations, and performance optimization.
- Maintain documentation for data sources, detection rules, use cases, dashboards, and operational procedures.
- Continuously evaluate new security technologies and recommend improvements to the SOC technology stack.
Experience
- 2 - 4 years of experience in SIEM engineering, security monitoring, detection engineering, or SOC engineering.
- Strong practical experience with Splunk and/or Cortex XSIAM.
- Candidates with experience working across both Splunk and XSIAM will be strongly preferred.
- Experience supporting enterprise-scale SIEM environments and multiple customer environments is an advantage.
📌 SIEM Engineer (Hyderabad)
🏢 HALA INFOSEC
📍 Hyderabad