12 Sep
|
ZySec AI
|
Mumbai
Job Type: Full-time
Location: Hyderabad, IndiaEmployment: Full-timeExperience: 4–6 yearsRole Description- Wazuh / SIEM administration and engineering- Log source onboarding & integration across Windows, Linux, Azure, Kubernetes, firewalls, WAF, EDR/XDR, VPN, DNS, applications and databases- Detection engineering – rules, decoders, parsers, correlation and security use cases- SIEM alert tuning and false-positive reduction- Detection development aligned with MITRE ATT&CK-; Azure and Kubernetes security monitoring- SIEM integration with SOAR, EDR, Threat Intelligence and ticketing platforms- Threat hunting and proactive detection improvement- SIEM troubleshooting, log-ingestion health and data-quality management- Supporting SOC analysts with investigation and incident response- Building and maintaining dashboards, KPIs, runbooks and detection documentationQualifications- 4–6 years of hands-on experience in SIEM Esp Wazuh, SOC, cybersecurity engineering, or security monitoring.- Experience working in an MSSP/SOC environment, supporting multiple customers, tenants, or security monitoring environments.- Strong hands-on experience with Wazuh or equivalent SIEM platforms.- Experience with multi-tenant SIEM operations, customer-specific log onboarding,
detection use cases, alert tuning, and monitoring requirements.- Experience onboarding and integrating logs from Windows, Linux, Azure, Kubernetes, firewalls, WAF, EDR/XDR, VPN, IAM/Entra ID, DNS, applications, and databases.- Strong understanding of SIEM architecture, log collection, parsing, normalization, correlation, detection rules, and alerting.- Experience developing, maintaining, and tuning SIEM use cases and detection rules.- Good understanding of MITRE ATT&CK;, threat detection, threat hunting, and common attack techniques.- Good knowledge of Microsoft Azure and Azure security/logging services.- Hands-on understanding of Kubernetes and container environments.- Strong knowledge of Windows, Linux, networking, and security technologies.- Experience integrating SIEM with SOAR, EDR/XDR, Threat Intelligence, ticketing, and other security platforms.- Ability to troubleshoot log ingestion, agents, collectors, parsers, indexing, storage, and SIEM performance.- Solid analytical, troubleshooting, documentation, and communication skills.- Ability to work with SOC L1/L2 analysts, customers, DevOps, infrastructure, and security teams.
📌 SIEM & Detection Engineer - Wazuh | Azure | SOC (Mumbai)
🏢 ZySec AI
📍 Mumbai