09 Oct
|
Artech Infosystems
|
India
09 Oct
Artech Infosystems
India
Description: Role: Security Engineer (Detection & Response / SIEM & SOAR)
Experience Range: 7 – 12 Years
Location: Chennai
Required Technical Skill Set: SIEM Engineering (Google Sec Ops / Chronicle / Splunk), Detection Engineering & Detection-as-Code (YARA-L / Sigma / Python), SOAR Automation & Playbook Development, Threat Hunting (Hypothesis-Driven & Behavioral Hunting), Security Telemetry Integration (Bind Plane, Open Telemetry, Logstash, Syslog, Cloud Logs), Secure CI/CD Pipelines (Git Hub Actions / Git Lab CI), MITRE Telecommunication&CK; Mapping
Desired Experience Range: 7 – 12 Years (with strong focus on SIEM/SOAR platform engineering, detection engineering, threat hunting, and incident response automation)
Role Descriptions:
Must-Have (Candidates must demonstrate depth in core security engineering and a blend/combination of the following specialisms)
• SIEM & Security Analytics Engineering: Deep hands-on experience designing, scaling, and operating enterprise next-gen SIEM platforms (Google Sec Ops / Chronicle, Splunk, Microsoft Sentinel), including data parsing, UDM mapping, indexing, and high-performance search optimization.
• Detection Engineering & Detection-as-Code: Proven track record authoring, testing, and operationalising threat detection rules using YARA-L, Sigma, SPL, or KQL. Practical experience applying Dev Ops/CI-CD principles to detection lifecycles (version control, automated validation, testing harnesses, and promotion).
• SOAR Automation & Orchestration: Advanced experience building automated incident triage, investigation, and response playbooks using modern SOAR platforms (Google Sec Ops SOAR / Siemplify, Splunk SOAR / Phantom, Cortex XSOAR),
utilizing custom Python scripts and REST API integrations.
• Proactive Threat Hunting: Strong capability in conducting hypothesis-driven and behavioral threat hunts across multi-cloud (GCP / Azure / AWS) and on-premises estates to identify advanced persistent threats (APTs) and evasive adversaries bypassing signature-based alerts.
• Security Telemetry Ingestion & Parsing: Practical experience configuring and optimizing log collectors and telemetry pipelines (Bind Plane OP, Open Telemetry Collector, Logstash, Fluentbit, Cloud Pub/Sub, Event Hubs), ensuring schema normalization and audit data integrity.
• Threat Frameworks & Contextual Enrichment: Extensive knowledge of MITRE Telecommunication&CK;, D3FEND, and Cyber Kill Chain frameworks to map detection coverage, evaluate visibility gaps, and enrich security signals with threat intelligence (GTI, STIX/TAXII).
• Scripting & CI/CD Tooling: High proficiency in Python for security automation, combined with hands-on experience utilizing Git, Git Hub Actions, or Git Lab CI for managing security infrastructure and detection repositories.
Valuable-to-Have
• Experience with AI/LLM-augmented threat hunting, agentic workflows, or Model Context Protocol (MCP) in security operations.
• Familiarity with endpoint detection (EDR/XDR like Crowd Strike Falcon, Microsoft Defender) and network security telemetry (Zeek, Suricata, VPC Flow Logs).
• Exposure to regulated banking environments and compliance requirements for security audit logging and financial incident response. • Industry certifications: GIAC (GCDA, GCIH, GCFA), Google Cloud Certified Professional Security Engineer, Splunk Certified Developer/Architect, or CISSP.
📌 IND_Senior Security Engineer (India)
🏢 Artech Infosystems
📍 India