Google Chronicle SIEM Engineer , SOC Automation Specialist & Platform (Hyderabad)

Google Chronicle SIEM Engineer , SOC Automation Specialist & Platform (Hyderabad)

24 Sep
|
Tata Consultancy Services
|
Hyderabad

24 Sep

Tata Consultancy Services

Hyderabad

Role & responsibilities

- Design, implement, and optimize Google Chronicle SIEM for scalable log ingestion, parsing, normalization, and enrichment.

- Create and updating correlation rules and use cases

- Develop and fine-tune detection rules, parsers, and correlation logic to improve threat detection accuracy.

- Integrate diverse log sources including firewalls, endpoint security, cloud services, IAM, ,network devices and etc.,.

- Build and maintain custom parsers and dashboards to enhance visibility into security events.

- Collaborate with threat hunting and detection engineering teams to identify and implement current detection logic.

- Design and implement automation workflows (SOAR-based or API-based) to reduce analyst workload and response time.

- Automate alert triage, enrichment, and response actions using scripts, playbooks, or orchestration tools.

- Integrate Google Chronicle with automation platforms (e.g., Cortex XSOAR, Splunk SOAR, Swimlane, or custom Python-based frameworks).

Bindplane :

- Deploy, configure, and manage Bind Plane agents across servers and cloud workloads.

- Set up data ingestion from multiple sources (Windows, Linux, databases, firewalls, cloud services).

- Normalize data schemas and forward logs to SIEM or observability tools (Chronicle, Elastic, Splunk).

- Configure pipelines for log transformation, labeling, and enrichment.

- Implement monitoring and alerts for agent health, performance, and log ingestion failures.

- Optimize ingestion pipelines to reduce latency and improve reliability.

Cribl:

- • Design, configure, and manage Cribl Stream pipelines for log, metric, and trace ingestion.

- Build data routing rules to send telemetry to multiple destinations (SIEM, S3, Data Lake).

- Implement data filtering, sampling, and transformation to optimize SIEM licensing.

- Integrate enterprise log sources including servers, firewalls, cloud platforms,



and APM tools

- Manage Cribl workers, leaders, and edge deployments.

- Troubleshoot ingestion delays, failed pipelines, and data parsing issues.

- Work with security teams to onboard new data sources into SIEM through Cribl.

- Develop proactive automation to reduce false positives, enhance correlation efficiency, and minimize noise.

- Continuously refine detection rules using data analytics and threat intelligence to eliminate redundant alerts.

- Conduct root cause analysis of recurring false positives and implement preventive detection improvements.

- Collaborate with threat intel teams to update use cases with the latest IOCs, TTPs, and MITRE ATT&CK; mappings.

- Conduct periodic reviews and audits of alert quality, accuracy, and SOC performance metrics.

- Develop and maintain detection engineering and automation frameworks with strong documentation.

- Partner with SOC operations, engineering, and threat hunting teams for continuous improvement initiatives.

- Participate in the design of proactive monitoring, AI/ML-based anomaly detection, and predictive automation models.

- Drive initiatives for SOC modernization, focusing on agility, scalability, and advanced analytics.

Required Skills and Experience

- 710 years of experience in Security Operations, SIEM Engineering, or SOC Automation.

- Strong hands-on experience with Google Chronicle SIEM (log pipelines, UDM, rule writing, dashboards).

- Proficiency in Python, API integrations, and automation frameworks (SOAR tools or custom automation scripts).

- Solid understanding of SOC processes, incident response workflows, and playbook design.

- Knowledge of MITRE ATT&CK;, threat intelligence feeds, and behavior-based detection models.

- Experience in reducing false positives, tuning detections, and implementing advanced correlation logic.

- Familiarity with cloud security logging (GCP, AWS, Azure) and endpoint security integrations.

📌 Google Chronicle SIEM Engineer , SOC Automation Specialist & Platform (Hyderabad)
🏢 Tata Consultancy Services
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: google chronicle siem engineer , soc automation specialist & platform (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: google chronicle siem engineer , soc automation specialist & platform (hyderabad) / hyderabad