Senior Detection Engineer (India)

Senior Detection Engineer (India)

17 Sep
|
Talanos Cyber Security
|
India

17 Sep

Talanos Cyber Security

India

Talanos Cybersecurity delivers managed SOC, identity governance, third-party risk management, dark web intelligence, continuous autonomous pentesting and security advisory services to mid-market and regulated organisations across the UK, Europe, South Africa, Botswana and India. We are CREST SOC accredited and certified ISO 27001 and ISO 9001.

We are building a dedicated Detection Engineering function and this is its founding role. We need someone who can engineer detections across enterprise SIEM platforms and who can also understand a customer's business well enough to know which detections actually matter to them. You will work across multiple SIEM platforms and sectors, with direct access to the CTO and real influence over our in-house product roadmap.

What you'll be doing

- Baseline and improve detection coverage for assigned customers against MITRE ATT&CK; and their own risk profile
- Author, test, version and maintain detection content across multiple SIEM platforms
- Determine the log sources and telemetry needed for a given detection outcome and troubleshoot integrations, parsers and data quality
- Work directly with customers to translate their business risk into monitoring requirements a SOC analyst can act on
- Build the correlation layer that connects our security services to one another (e.g. turning dark web credential exposures into tuned identity detections)
- Track the threat landscape and build a reusable detection library so work for one customer raises the baseline for all

What you'll need

You don't need to tick every box below, but most of these should describe you:

- 6+ years in cybersecurity, with real hands-on experience in security operations,



SIEM engineering or detection content
- Deep, practical experience with at least one enterprise SIEM (e.g. Microsoft Sentinel, Splunk, IBM QRadar, Elastic Security, Google SecOps, Sumo Logic) and confidence working across more than one
- Demonstrable experience authoring detection logic in a query language such as KQL, SPL, EQL, Lucene, YARA-L or Sigma
- Strong working knowledge of MITRE ATT&CK; used for coverage and gap analysis, not just as a reporting label
- Practical understanding of log sources across Windows, Linux, cloud platforms, identity systems, network, email and EDR
- Ability to hold a credible conversation with a customer about their business and convert it into monitoring requirements
- Explicit written and spoken English

Nice to have

- Python or PowerShell scripting; detection-as-code workflows using Git and CI pipelines
- Purple team experience, or use of Atomic Red Team, Caldera or a commercial breach and attack simulation platform
- Structured, hypothesis-driven threat hunting experience
- Identity security experience (identity governance, privileged access, privileged account monitoring)
- Cloud or detection certifications (AZ-500, SC-200, AWS Security Specialty, GCDA, GCIA, GCFA, GCED, OSCP)

What we offer





- Genuine ownership of a new discipline, reporting directly to the CTO
- Breadth across multiple customers, sectors and SIEM platforms
- A funded training and certification budget
- Standard business hours, no shift work and no on-call rota (with regular calls overlapping into the UK afternoon/evening, roughly 1:30pm-9:30pm IST)
- A clear path to leading the function as it grows

To apply, please submit your CV along with a short note on one detection you personally designed and built: what it was for, what evidence it relied on, and how you knew it worked.

Pay: ₹100,000.00 - ₹250,000.00 per year

Benefits:

- Paid sick time
- Paid time off
- Work from home

Application Question(s):

- Describe a detection you personally designed and built. What was it for, what evidence did it rely on, how did you confirm it worked?
- Which SIEM platform(s) have you personally authored detection content in (not just administered), and which query language(s) have you used (e.g. KQL, SPL, Sigma)?
- How many years of hands-on experience do you have specifically authoring or maintaining detection logic, as distinct from monitoring or triaging alerts?
- Give an example of a time you explained a security risk or detection gap to a non-technical stakeholder or customer. What was the situation and how did you approach it?
- This role involves occasional travel to Delhi (roughly once a month) and regular working hours that overlap into the UK afternoon/evening (approx. 1:30pm-9:30pm IST). Are you comfortable with this?
- What is your current notice period?

Work Location: Hybrid remote in Delhi, Delhi

📌 Senior Detection Engineer (India)
🏢 Talanos Cyber Security
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior detection engineer (india) / india