19 Sep
|
Capgemini
|
Bengaluru
19 Sep
Capgemini
Bengaluru
Your Role
As a
SIEM Engineer L3
at Capgemini, you will be responsible for ensuring that the SOC has accurate, complete, normalized, enriched, and queryable security telemetry required for monitoring, detection, investigation, threat hunting, automation, and reporting. You will design and implement data onboarding solutions, develop integrations and parsers, validate data quality, and collaborate with multiple teams to build scalable and reliable telemetry pipelines.
- Design, implement, and optimize security telemetry ingestion pipelines into SIEM, Data Lake, SOAR, and other SOC platforms using native and custom integrations.
- Build, configure, and maintain connectors, API integrations, Azure Functions, Event Hub pipelines, syslog collectors, and custom ingestion mechanisms for diverse security data sources.
- Develop and manage parsing, normalization, schema mapping, enrichment, deduplication, and transformation logic using KQL, Regex, Grok, ASIM, OCSF, and related frameworks.
- Collaborate with Detection Engineering, Platform Engineering, and technology owners to ensure telemetry supports detection use cases, operational stability, and cost-effective scalability.
- Monitor, troubleshoot, and improve ingestion pipelines, data quality, connector health, telemetry coverage,
and onboarding processes while maintaining comprehensive technical documentation.
Your Profile
- Hands-on experience with Microsoft Sentinel, security telemetry onboarding, custom connector development, API integrations, and large-scale log ingestion platforms such as Azure Data Explorer, Azure Data Lake, Databricks, Cribl Stream, Logstash, or syslog-ng.
- Robust understanding of log collection methodologies including syslog, APIs, agent-based collection, cloud-native integrations, event streaming, custom logs, Azure Monitor Agent, Event Hub, and Azure Functions.
- Expertise in data parsing, normalization, schema alignment, enrichment, and transformation using KQL, Regex, Grok, ASIM, OCSF, and security data models.
- Good knowledge of security telemetry across endpoint, identity, email, network, firewall, DNS, cloud, SaaS, OT/ICS, vulnerability management, and asset inventory environments, along with MITRE ATT&CK; data source mapping.
- Experience in troubleshooting telemetry pipelines, validating data quality, managing ingestion monitoring, ensuring analyst usability, supporting detection requirements, and maintaining detailed documentation in regulated enterprise environments.
Work location : Mumbai / Bengaluru
📌 SIEM Engineer (Bengaluru)
🏢 Capgemini
📍 Bengaluru