Job DescriptionPlease share CV to
[email protected] with the below details:
NTotal Experience-
nCurrent ctc-
Nexpected ctc-
nNotice Period-
NSOC Detection and Automation Engineer
NExperience required- 6 to10 years
NOverview
nResponsible for enhancing our security posture by developing, implementing, and maintaining detection content within the SIEM. A key focus of this position will be leveraging our SIEMs automation and AI capabilities to streamline level 1 security incident triage and response, thereby increasing the efficiency and effectiveness of our Security Operations Center (SOC).
NMandatory Skills- Detection Engineering, Detection Rule/Use Case Development, SIEM/SOAR, MITRE ATTACK, Threat Hunting, Python/PowerShell, SOAR Playbooks, Automation, API Integrations, Rule Tuning & False Positive Reduction, EDR/XDR, Forensic Investigation, SIEM Data Ingestion/Parsing, Cloud Security Monitoring, Threat Intelligence etc
NResponsibilities--We are seeking a highly skilled and motivated SOC Engineer to join our security operations team. This critical role will be responsible for:
NDetection Engineering andContent Development
N
n
- Design, develop, test, and deploy high-fidelity detection rules, correlational logic, and behavioral models within SIEM.
N
- Translate threat intelligence, known vulnerabilities, and observed attack techniques (e.G., MITRE ATT&CK; framework) into actionable detection content.
N
- Continuously review andtune existing detection content to minimize false positives while maximizing coverage of emerging threats.
N
- Ensure all detection content is mapped to relevant security controls and incident response playbooks.
N
nAutomation and Efficiency
N
n
- Develop, implement, and maintain automation playbooks (using our SIEMs automation engine) to automate repetitive Level 1 incident triage tasks, data enrichment, and initial response actions.
N
- Integrate SIEM with other security tools and enterprise platforms via APIs and connectors to facilitate seamless data flow and automated response.
N
- Explore and apply SIEMsbuilt-in AI/ML capabilities to improve alert prioritization, anomaly detection, and automated incident clustering.
N
- Document automation logic, workflows, and effectiveness metrics.
N
nPlatform Management and Optimization
N
n
- Act as a subject matter expert for the SIEM, including data ingestion, logging policies, and platform health.
N
- Collaborate with Security Architecture and IT teams to onboard new data sources into SIEM, ensuring proper normalization and parsing for detection use cases.
N
- Monitor platform performance, troubleshoot content execution issues, and assist in maintaining the overall operational stability of the SIEM environment.
N
nCollaboration and Improvement
N
n
- Work closely withSOC Analysts, Threat Hunters,
and Incident Responders to understand their needs and develop content that directly supports their operations.
N
- Participate in post-incident review processes to identify detection and automation gaps and drive improvements.
N
- Stay current with the latest cybersecurity trends, attack vectors, and SIEM features and updates.
N
nQualifications
nRequired Skills and Experience
N
n
- 3+ years of experience in Security Operations, Threat Hunting, or Detection Engineering.
N
- Demonstrable expertise in designing and implementing detection content using a SIEM/SOAR platform (strong preference for Palo Alto Networks XSIAM/Cortex XSOAR experience).
N
- Deep understanding of the cyber kill chain and MITRE ATT&CK; framework.
N
- Proficiency in scripting languages (e.G., Python, PowerShell) for automation and data manipulation.
N
- Solid knowledge of security logging formats, network protocols, operating systems (Windows, Linux), and cloud environments.
N
- Experience with API integrations and developing automation playbooks (SOAR).
N
- Excellent analytical, problem-solving, and communication skills.
N
nPreferred Qualifications
N
n
- Hands-on experience with Palo Alto Networks XSIAM, including content creation and automation development.
N
- Relevant industry certifications (e.G., PCNSE, PCSAE, GCIH, GCFA, CISSP).
N
- Experience with cloud security monitoring (AWS, Azure, GCP).
N
- Familiarity with threatintelligence platforms and integrating intelligence feeds into detection logic.
N
📌 Dart Engineer (Karnataka)
🏢 HCLSoftware
📍 Karnataka