24 Sep
|
Tata Consultancy Services
|
Hyderabad
24 Sep
Tata Consultancy Services
Hyderabad
Role & responsibilities
- Design, implement, and optimize Google Chronicle SIEM for scalable log ingestion, parsing, normalization, and enrichment.
- Create and updating correlation rules and use cases
- Develop and fine-tune detection rules, parsers, and correlation logic to improve threat detection accuracy.
- Integrate diverse log sources including firewalls, endpoint security, cloud services, IAM, ,network devices and etc.,.
- Build and maintain custom parsers and dashboards to enhance visibility into security events.
- Collaborate with threat hunting and detection engineering teams to identify and implement current detection logic.
- Design and implement automation workflows (SOAR-based or API-based) to reduce analyst workload and response time.
- Automate alert triage, enrichment, and response actions using scripts, playbooks, or orchestration tools.
- Integrate Google Chronicle with automation platforms (e.g., Cortex XSOAR, Splunk SOAR, Swimlane, or custom Python-based frameworks).
Bindplane :
- Deploy, configure, and manage Bind Plane agents across servers and cloud workloads.
- Set up data ingestion from multiple sources (Windows, Linux, databases, firewalls, cloud services).
- Normalize data schemas and forward logs to SIEM or observability tools (Chronicle, Elastic, Splunk).
- Configure pipelines for log transformation, labeling, and enrichment.
- Implement monitoring and alerts for agent health, performance, and log ingestion failures.
- Optimize ingestion pipelines to reduce latency and improve reliability.
Cribl:
- • Design, configure, and manage Cribl Stream pipelines for log, metric, and trace ingestion.
- Build data routing rules to send telemetry to multiple destinations (SIEM, S3, Data Lake).
- Implement data filtering, sampling, and transformation to optimize SIEM licensing.
- Integrate enterprise log sources including servers, firewalls, cloud platforms,
and APM tools
- Manage Cribl workers, leaders, and edge deployments.
- Troubleshoot ingestion delays, failed pipelines, and data parsing issues.
- Work with security teams to onboard new data sources into SIEM through Cribl.
- Develop proactive automation to reduce false positives, enhance correlation efficiency, and minimize noise.
- Continuously refine detection rules using data analytics and threat intelligence to eliminate redundant alerts.
- Conduct root cause analysis of recurring false positives and implement preventive detection improvements.
- Collaborate with threat intel teams to update use cases with the latest IOCs, TTPs, and MITRE ATT&CK; mappings.
- Conduct periodic reviews and audits of alert quality, accuracy, and SOC performance metrics.
- Develop and maintain detection engineering and automation frameworks with strong documentation.
- Partner with SOC operations, engineering, and threat hunting teams for continuous improvement initiatives.
- Participate in the design of proactive monitoring, AI/ML-based anomaly detection, and predictive automation models.
- Drive initiatives for SOC modernization, focusing on agility, scalability, and advanced analytics.
Required Skills and Experience
- 710 years of experience in Security Operations, SIEM Engineering, or SOC Automation.
- Strong hands-on experience with Google Chronicle SIEM (log pipelines, UDM, rule writing, dashboards).
- Proficiency in Python, API integrations, and automation frameworks (SOAR tools or custom automation scripts).
- Solid understanding of SOC processes, incident response workflows, and playbook design.
- Knowledge of MITRE ATT&CK;, threat intelligence feeds, and behavior-based detection models.
- Experience in reducing false positives, tuning detections, and implementing advanced correlation logic.
- Familiarity with cloud security logging (GCP, AWS, Azure) and endpoint security integrations.
📌 Google Chronicle SIEM Engineer , SOC Automation Specialist & Platform (Hyderabad)
🏢 Tata Consultancy Services
📍 Hyderabad