SME - Security Investigations, SIEM
Pune, Maharashtra
Job Summary
Division Cybersecurity- AppSec Track SOC- Detection Engineering Level L3 Location Offshore (India) Years of Experience • 10+ years of experience in SIEM engineering, Splunk content development, detection engineering, SOC analytics, or threat-detection use cases. Responsibilities • Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content. • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high-quality Splunk detections and analytics. • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise. • Design and develop correlation searches, risk-based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk. • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement. • Map detections to MITRE ATT&ck; techniques, Client threat scenarios, control objectives, and relevant assets or business services. • Analyze false positives, missed detections, alert quality, detection gaps, and data-quality issues; implement tuning recommendations through approved change processes. • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics. • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection. • Maintain the detection/use-case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics. • Automate detection deployment, testing, version control, and content quality checks where feasible. • Mentor L2 analysts and provide technical reviews for detection-content changes. Technical Requirements • Expert-level Splunk Search Processing Language, correlation searches, Enterprise Security, risk-based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards. • Strong experience with Splunk Cloud and enterprise-scale security content engineering. • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security-control platforms. • Deep knowledge of MITRE ATT&ck;, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks. • Experience with detection-as-code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation. • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability. • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections. • Understanding of SOC workflows, incident response, threat hunting, false-positive management, and detection-performance metrics. • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred. Soft Skills • Excellent communication and presentation skills. • Robust problem-solving and critical thinking skills. • Exceptional project management and organizational abilities. • Team collaboration and leadership skills. • Client-focused approach with a commitment to delivering exceptional customer service. Certifications (Good to have) Good to have relevant certificates like (any of the below): • Splunk Enterprise Security Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Certified Admin. • GCIA, GCIH, GMON, CISSP, CySA+, or equivalent detection/security-operations certification is preferred. Educational Qualifications • University degree in IT or/and IT Security. • Bachelor’s degree in computer science/ IT or any relevant fields.
Key Responsibilities
Division Cybersecurity- AppSec Track SOC- Detection Engineering Level L3 Location Offshore (India) Years of Experience • 10+ years of experience in SIEM engineering, Splunk content development, detection engineering, SOC analytics, or threat-detection use cases. Responsibilities • Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content. • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high-quality Splunk detections and analytics. • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise. • Design and develop correlation searches, risk-based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk. • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement. • Map detections to MITRE ATT&ck; techniques, Client threat scenarios, control objectives, and relevant assets or business services. • Analyze false positives, missed detections, alert quality, detection gaps, and data-quality issues; implement tuning recommendations through approved change processes.
• Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics. • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection. • Maintain the detection/use-case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics. • Automate detection deployment, testing, version control, and content quality checks where feasible. • Mentor L2 analysts and provide technical reviews for detection-content changes. Technical Requirements • Expert-level Splunk Search Processing Language, correlation searches, Enterprise Security, risk-based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards. • Strong experience with Splunk Cloud and enterprise-scale security content engineering. • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security-control platforms. • Deep knowledge of MITRE ATT&ck;, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks. • Experience with detection-as-code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation. • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability. • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections. • Understanding of SOC workflows, incident response, threat hunting, false-positive management, and detection-performance metrics. • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred. Soft Skills • Excellent communication and presentation skills. • Strong problem-solving and critical thinking skills. • Exceptional project management and organizational abilities. • Team collaboration and leadership skills. • Client-focused approach with a commitment to delivering exceptional customer service. Certifications (Good to have) Good to have relevant certificates like (any of the below): • Splunk Enterprise Security Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Certified Admin. • GCIA, GCIH, GMON, CISSP, CySA+, or equivalent detection/security-operations certification is preferred. Educational Qualifications • University degree in IT or/and IT Security. • Bachelor’s degree in computer science/ IT or any relevant fields.
Skill Requirements
Division Cybersecurity- AppSec Track SOC- Detection Engineering Level L3 Location Offshore (India) Years of Experience • 10+ years of experience in SIEM engineering, Splunk content development, detection engineering, SOC analytics, or threat-detection use cases. Responsibilities • Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content. • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high-quality Splunk detections and analytics. • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise. • Design and develop correlation searches, risk-based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk. • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement. • Map detections to MITRE ATT&ck; techniques, Client threat scenarios, control objectives, and relevant assets or business services. • Analyze false positives, missed detections, alert quality, detection gaps, and data-quality issues; implement tuning recommendations through approved change processes. • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics. • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection. • Maintain the detection/use-case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics. • Automate detection deployment, testing, version control, and content quality checks where feasible. • Mentor L2 analysts and provide technical reviews for detection-content changes. Technical Requirements • Expert-level Splunk Search Processing Language, correlation searches, Enterprise Security, risk-based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards. • Strong experience with Splunk Cloud and enterprise-scale security content engineering. • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security-control platforms. • Deep knowledge of MITRE ATT&ck;, threat detection methodologies,
attacker behavior, cyber kill chain, and common detection frameworks. • Experience with detection-as-code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation. • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability. • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections. • Understanding of SOC workflows, incident response, threat hunting, false-positive management, and detection-performance metrics. • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred. Soft Skills • Excellent communication and presentation skills. • Strong problem-solving and critical thinking skills. • Exceptional project management and organizational abilities. • Team collaboration and leadership skills. • Client-focused approach with a commitment to delivering exceptional customer service. Certifications (Good to have) Good to have relevant certificates like (any of the below): • Splunk Enterprise Security Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Certified Admin. • GCIA, GCIH, GMON, CISSP, CySA+, or equivalent detection/security-operations certification is preferred. Educational Qualifications • University degree in IT or/and IT Security. • Bachelor’s degree in computer science/ IT or any relevant fields.
Other Requirements
Division Cybersecurity- AppSec Track SOC- Detection Engineering Level L3 Location Offshore (India) Years of Experience • 10+ years of experience in SIEM engineering, Splunk content development, detection engineering, SOC analytics, or threat-detection use cases. Responsibilities • Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content. • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high-quality Splunk detections and analytics. • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise. • Design and develop correlation searches, risk-based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk. • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement. • Map detections to MITRE ATT&ck; techniques, Client threat scenarios, control objectives, and relevant assets or business services. • Analyze false positives, missed detections, alert quality, detection gaps, and data-quality issues; implement tuning recommendations through approved change processes. • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics. • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection. • Maintain the detection/use-case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics. • Automate detection deployment, testing, version control, and content quality checks where feasible. • Mentor L2 analysts and provide technical reviews for detection-content changes. Technical Requirements • Expert-level Splunk Search Processing Language, correlation searches, Enterprise Security, risk-based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards. • Strong experience with Splunk Cloud and enterprise-scale security content engineering. • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security-control platforms. • Deep knowledge of MITRE ATT&ck;, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks. • Experience with detection-as-code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation. • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability. • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections. • Understanding of SOC workflows, incident response, threat hunting, false-positive management, and detection-performance metrics. • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred. Soft Skills • Excellent communication and presentation skills. • Strong problem-solving and critical thinking skills. • Exceptional project management and organizational abilities. • Team collaboration and leadership skills. • Client-focused approach with a commitment to delivering exceptional customer service. Certifications (Good to have) Good to have relevant certificates like (any of the below): • Splunk Enterprise Security Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Certified Admin. • GCIA, GCIH, GMON, CISSP, CySA+, or equivalent detection/security-operations certification is preferred. Educational Qualifications • University degree in IT or/and IT Security. • Bachelor’s degree in computer science/ IT or any relevant fields.
📌 SME - Security Investigations, SIEM (Pune)
🏢 HCLTech
📍 Pune