17 Sep
|
Kiya.ai
|
Bengaluru
We are looking for Senior SIEM Engineer to support a clients Next Generation Security Event Management program. The client is migrating SIEM capability from IBM QRadar to Elastic Security Stack and needs experienced engineers to support data-source onboarding, Elastic ingestion, ECS normalization, and detection logic development.
Role Summary The Senior SIEM Engineer will be responsible for onboarding and operationalizing prioritized security telemetry into Elastic Security, including creation and maintenance of data streams, ingest pipelines, index templates, field mappings, ECS normalization, and detection rules. The role requires strong hands-on experience in Elastic SIEM engineering, security log ingestion, parsing, detection engineering, and working with SOC/security monitoring teams.
Key Responsibilities
- Assess security log sources for onboarding readiness, including connectivity, log format, volume, collection method, parsing needs, data quality, field availability, and detection suitability.
- Design, configure, test, and maintain Elastic data streams, index templates, component templates, mappings, naming conventions, lifecycle policies, and retention settings.
- Develop and maintain Elastic ingest pipelines to parse, enrich, transform, and normalize security events.
- Map source fields to Elastic Common Schema (ECS) or approved security data models.
- Validate end-to-end telemetry ingestion into Elastic, including timestamp accuracy, parsing success, field extraction, mapping conflicts, duplicate events, data loss, and pipeline failures.
- Design, develop, test, tune, and deploy detection rules and security use cases in Elastic Security.
- Build detection logic using KQL, EQL, ES|QL, threshold rules, correlation logic, exceptions, risk scoring,
and rule metadata.
- Map detections to relevant MITRE ATT&CK; tactics, techniques, and sub-techniques.
- Document detection logic, test evidence, tuning decisions, false-positive considerations, known limitations, and production-readiness recommendations.
- Troubleshoot ingestion, parsing, ECS mapping, indexing, alerting, detection, and performance issues across Elasticsearch and Kibana.
- Partner with SIEM Engineering, SOC, Threat Intelligence, application owners, source-system owners, and third-party teams such as Cribl.
- Maintain technical documentation, runbooks, implementation evidence, deployment records, risks, dependencies, and operational handover artifacts.
- Provide regular status updates on progress, blockers, risks, dependencies, and decisions required.
Required Skills and Experience
- 7+ years in cybersecurity / SIEM engineering, with at least 3+ years of hands-on Elastic Security / Elasticsearch / Kibana experience preferred.
- Strong hands-on experience as a SIEM Engineer / Detection Engineer / Security Data Engineer.
- Practical experience with Elastic Security / Elastic SIEM / Elasticsearch / Kibana.
- Experience creating and maintaining data streams, ingest pipelines, mappings, index templates, and lifecycle configurations.
- Strong knowledge of security log ingestion, parsing, enrichment, transformation, and normalization.
- Experience with Elastic Common Schema (ECS) mapping and data-model alignment.
- Hands-on experience writing detection rules using KQL, EQL, ES|QL, threshold logic, and correlation logic.
- Good understanding of SOC operations, alert triage, incident detection, and security monitoring use cases.
- Experience mapping detections to MITRE ATT&CK;.
- Ability to troubleshoot log ingestion, parsing, indexing, pipeline, and alerting issues.
- Strong documentation skills, including runbooks, design notes, validation evidence, and operational handover documents.
- Ability to work independently with multiple technical stakeholders and source-system owners.
Good to Have
- Experience with IBM QRadar to Elastic migration.
- Experience with Cribl for log routing, transformation, and enrichment.
- Experience with cloud, endpoint, identity, network, firewall, application, and infrastructure log sources.
- Familiarity with change-management and production deployment processes in enterprise environments.
- Experience in regulated or large enterprise environments.
Tools / Technologies
- Elastic Security
- Elasticsearch
- Kibana
- Elastic Ingest Pipelines
- Elastic Common Schema
- KQL / EQL / ES|QL
- MITRE ATT&CK;
- Cribl
- IBM QRadar
- Jira / Confluence or similar tracking and documentation tools
Expected Profile
- Senior-level SIEM professional with robust hands-on Elastic engineering experience.
- Must be comfortable with both data engineering for security telemetry and detection engineering.
- Should be proactive, documentation-focused, and able to coordinate across SOC, security engineering, application, infrastructure, and vendor teams.
📌 Senior SIEM Engineer (Bengaluru)
🏢 Kiya.ai
📍 Bengaluru