12 Sep
|
ZySec AI
|
Hyderabad
12 Sep
ZySec AI
Hyderabad
Location: Hyderabad, India
nEmployment: Full-time
nExperience: 4–6 years
nRole Description
n
n
- Wazuh / SIEM administration and engineering
n
- Log source onboarding & integration across Windows, Linux, Azure, Kubernetes, firewalls, WAF, EDR/XDR, VPN, DNS, applications and databases
n
- Detection engineering – rules, decoders, parsers, correlation and security use cases
n
- SIEM alert tuning and false-positive reduction
n
- Detection development aligned with MITRE ATT&CK;
n
- Azure and Kubernetes security monitoring
n
- SIEM integration with SOAR, EDR, Threat Intelligence and ticketing platforms
n
- Threat hunting and proactive detection improvement
n
- SIEM troubleshooting, log-ingestion health and data-quality management
n
- Supporting SOC analysts with investigation and incident response
n
- Building and maintaining dashboards, KPIs, runbooks and detection documentation
n
nQualifications
n
n
- 4–6 years of hands-on experience in SIEM Esp Wazuh, SOC, cybersecurity engineering, or security monitoring.
n
- Experience working in an MSSP/SOC environment, supporting multiple customers, tenants, or security monitoring environments.
n
- Strong hands-on experience with Wazuh or equivalent SIEM platforms.
n
- Experience with multi-tenant SIEM operations, customer-specific log onboarding,
detection use cases, alert tuning, and monitoring requirements.
n
- Experience onboarding and integrating logs from Windows, Linux, Azure, Kubernetes, firewalls, WAF, EDR/XDR, VPN, IAM/Entra ID, DNS, applications, and databases.
n
- Strong understanding of SIEM architecture, log collection, parsing, normalization, correlation, detection rules, and alerting.
n
- Experience developing, maintaining, and tuning SIEM use cases and detection rules.
n
- Good understanding of MITRE ATT&CK;, threat detection, threat hunting, and common attack techniques.
n
- Good knowledge of Microsoft Azure and Azure security/logging services.
n
- Hands-on understanding of Kubernetes and container environments.
n
- Strong knowledge of Windows, Linux, networking, and security technologies.
n
- Experience integrating SIEM with SOAR, EDR/XDR, Threat Intelligence, ticketing, and other security platforms.
n
- Ability to troubleshoot log ingestion, agents, collectors, parsers, indexing, storage, and SIEM performance.
n
- Solid analytical, troubleshooting, documentation, and communication skills.
n
- Ability to work with SOC L1/L2 analysts, customers, DevOps, infrastructure, and security teams.
n
📌 SIEM & Detection Engineer - Wazuh | Azure | SOC (Hyderabad)
🏢 ZySec AI
📍 Hyderabad