Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)
We are looking for experienced Cybersecurity to join our team.
Candidates with relevant experience and immediate or short joining availability are encouraged to apply, please email your updated resume to
[email protected] for further consideration.
We look forward to connecting with talented professionals in the Cybersecurity domain.
Apply now or tag someone who would be a excellent fit!
- SOC L3 Engineer (Elastic SIEM & SOAR)
Location: Bengaluru
Role: SOC L3 / Senior Security Operations Engineer
Role Summary
Seeking an experienced SOC L3 professional with strong expertise in Elastic Security (SIEM) and SOAR platforms. The candidate should possess hands-on experience in SIEM implementation, administration, content engineering, threat hunting, incident response, and SOC optimization across multiple SIEM technologies such as Microsoft Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic, or similar platforms.
Key Responsibilities
Lead L3 investigations for complex security incidents and advanced threats.
Design, implement, and optimize Elastic SIEM and Elastic Security deployments.
Develop and maintain SOAR playbooks, automation workflows, and integrations.
Build and tune detection rules, correlation logic, dashboards, alerts, and threat hunting content.
Support end-to-end SIEM implementation including onboarding log sources, parsing, normalization, and data pipelines.
Perform threat hunting, malware analysis, and root cause investigations.
Provide technical guidance to L1/L2 analysts and lead incident response activities.
Integrate threat intelligence feeds and improve detection maturity.
Conduct use case development, validation, and security monitoring enhancements.
Participate in SOC transformation, SIEM migrations, and platform evaluations.
Required Technical Skills
Strong hands-on experience with Elastic SIEM / Elastic Security.
Experience with Elastic Defend, Kibana, Elasticsearch, Logstash, Beats, Fleet, and detection engineering.
Hands-on experience in SOAR implementation and automation orchestration.
Experience implementing or managing other SIEM platforms such as Microsoft Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic, Stellar Cyber, or equivalent.
Strong understanding of Windows, Linux, Active Directory, Azure, AWS, networking, and cloud security.
Knowledge of MITRE ATT&CK;, Cyber Kill Chain, IOC analysis, and threat intelligence.
Experience with scripting (Python, PowerShell, Bash) for automation.
Understanding of EDR/XDR, NDR, Email Security, IAM, and Security Controls integration.
Preferred Certifications
Elastic Certified Engineer, Microsoft SC-200, AZ-500, Splunk, QRadar, GCIH, GCIA, CEH, CISSP, or equivalent certifications.
Soft Skills
Strong analytical and troubleshooting skills, stakeholder communication, client-facing experience, documentation skills, mentoring capability, and ability to lead critical security incidents.
Deal Breaker Skill
Elastic Search
Mandatory Skills
Elastic Search
Elastic SIEM
ELK
Soar Automation
Elastic Security
Candidates with the relevant experience and skills mentioned above are requested to share their updated resumes to
[email protected].
Kindly include the following details in your CV/email while submitting your application to help us process your profile efficiently.
Total Exp and Relevant Exp: - Current Company: Current CTC: Expected CTC: Current Location:Notice Period
📌 Hiring: SOCEngineer (Elastic SIEM & SOAR) (Bangalore Rural)
🏢 IT MNC
📍 Bangalore Rural