SIEM Integration Architect
4 days ago
What Success Looks Like In This Role
- Lead the integration of alarm/data feeds from multiple SIEM platforms (e.g., Splunk, LogRhythm, Securonix) into Microsoft Sentinel.
- Configure and manage Cribl pipelines to collect, filter, transform, and enrich raw data before forwarding to Sentinel.
- Design and implement data normalization strategies to ensure consistent formatting, tagging, and field mapping.
- Build and maintain data ingestion workflows, ensuring optimized performance, scalability, and reliability.
- Develop and maintain custom Sentinel connectors, KQL queries, workbooks, and analytics rules.
- Implement and tune SOAR automation playbooks using Logic Apps or integrated response tools.
- Collaborate with resolver teams (Platform, Application, CloudOps) for end-to-end use case implementation.
- Act as SME for Microsoft Sentinel and Cribl architecture in client-facing and technical forums.
- Troubleshoot integration and ingestion issues across hybrid and cloud-native infrastructures.
- Establish alert pipelines to bring security alerts/alarms from legacy SIEM tools into Sentinel for centralized monitoring.
- Ensure data integrity, compliance, and auditability in accordance with customer and regulatory requirements.
- Generate technical documentation, integration standards, and data flow diagrams.
- Provide expert guidance to SOC analysts and security engineers on new use cases and data onboarding.
- Stay updated on current and emerging threats to enhance detection and response capabilities.
You will be successful in this role if you have:
- Required Skills & Experience:
- 10–15 years of experience in cybersecurity, with a strong technical background in SIEM tools and security data architecture.
- Proven experience with Microsoft Sentinel, including data connectors, KQL, and automation via Logic Apps.
- Hands-on expertise in Cribl: stream design, data parsing, enrichment, routing, and performance tuning.
- Experience with multiple SIEM platforms (e.g., Splunk, LogRhythm, Securonix) and their alarm/log structures.
- Deep understanding of SIEM data ingestion models, log collection, and telemetry pipelines.
- Familiarity with cloud-native services (Azure, AWS, GCP) and their logging/integration mechanisms.
- Scripting experience with Python and PowerShell for integration and automation tasks.
- Strong knowledge of security frameworks (MITRE ATT&CK, NIST, OWASP, etc.) and their application in real-world use cases.
- Ability to troubleshoot complex integration issues involving multiple data sources and tools.
Key Qualifications
- Bachelor's degree in Computer Science, Information Security, or related field.
- Certifications preferred: Microsoft SC-200, Security+, GCIH, CEH, Cribl Certified Admin.
- Excellent communication and stakeholder management skills.
- Strong problem-solving mindset and attention to detail.
- Ability to mentor junior staff and lead technical discussions.
Unisys is proud to be an equal opportunity employer that considers all qualified applicants without regard to age, blood type, caste, citizenship, color, disability, family medical history, family status, ethnicity, gender, gender expression, gender identity, genetic information, marital status, national origin, parental status, pregnancy, race, religion, sex, sexual orientation, transgender status, veteran status or any other category protected by law.
This commitment includes our efforts to provide for all those who seek to express interest in employment the opportunity to participate without barriers. If you are a US job seeker unable to review the job opportunities herein, or cannot otherwise complete your expression of interest, without additional assistance and would like to discuss a request for reasonable accommodation, please contact our Global Recruiting organization at or alternatively Toll Free: Prompt 4). US job seekers can find more information about Unisys' EEO commitment here.
-
Siem Administrator
2 weeks ago
Bengaluru, Karnataka, India Blue Mantis Full time**Description**: The SIEM Administrator is a critical and essential member of our 24x7 Security Operations team, responsible for the configuration of SIEM integrations, development and tuning of detection models, and customization of dashboards and reports. **Key Responsibilities**: - Operates and maintains SIEM tools and components, such as log...
-
Elastic Engineer – Elasticsearch
1 week ago
Bengaluru, Karnataka, India, Karnataka GIOS Technology Full timeI am hiring for Elastic Engineer – Elasticsearch / SIEM / ObservabilityLocation: Bengaluru, Karnataka, IndiaJob DescriptionArchitect, deploy, and maintain the Elastic SIEM stack (ES/Kibana/Logstash/Beats) for robust security monitoring in cloud and on-prem environments. Develop, tune, and operationalize high-fidelity detection rules and alerts based on...
-
Elastic Engineer – Elasticsearch
1 week ago
Bengaluru, India GIOS Technology Full timeI am hiring for Elastic Engineer – Elasticsearch / SIEM / Observability Location: Bengaluru, Karnataka, India Job Description Architect, deploy, and maintain the Elastic SIEM stack (ES/Kibana/Logstash/Beats) for robust security monitoring in cloud and on-prem environments. Develop, tune, and operationalize high-fidelity detection rules and alerts based on...
-
Elastic Engineer – Elasticsearch
1 week ago
Bengaluru, India GIOS Technology Full timeI am hiring for Elastic Engineer – Elasticsearch / SIEM / Observability Location: Bengaluru, Karnataka, India Job Description Architect, deploy, and maintain the Elastic SIEM stack (ES/Kibana/Logstash/Beats) for robust security monitoring in cloud and on-prem environments. Develop, tune, and operationalize high-fidelity detection rules and alerts based on...
-
Elastic Engineer – Elasticsearch
5 days ago
Bengaluru, India GIOS Technology Full timeI am hiring for Elastic Engineer – Elasticsearch / SIEM / Observability Location: Bengaluru, Karnataka, India Job Description Architect, deploy, and maintain the Elastic SIEM stack (ES/Kibana/Logstash/Beats) for robust security monitoring in cloud and on-prem environments. Develop, tune, and operationalize high-fidelity detection rules and alerts based on...
-
Csa Siem Admin
2 weeks ago
Bengaluru, Karnataka, India Deutsche Bank Full time**CSA SIEM Admin (Sentinel), AVP**: **Job ID**:R0386120 **Full/Part-Time**:Full-time **Regular/Temporary**:Regular **Listed**:2025-04-29 **Location**:Bangalore **Position Overview**: **Job Title: CSA SIEM Admin (Sentinel)** **Corporate Title: Assistant Vice President** **Location: Bangalore, India** **Role Description** The COO Chief Information...
-
Siem Administrator
2 days ago
Bengaluru, Hyderabad, Pune, India Infosys Full timeJob description: Cyber security Platform Lead /Mgr (Qradar)8-12+ years of experience in managing platform activities such as Qradar SIEM at enterprise level/large scale deployment.Responsible for new implementation, administration, and maintenance of platform along with providing required reports to management and clientHands on experience and deep...
-
Integration Architect
2 weeks ago
Bengaluru, Karnataka, India Torry Harris Full timeAt Torry Harris, we are seeking a talented and experienced Integration Architect to join our team. As an Integration Architect, you will play a crucial role in designing and implementing robust, scalable, and efficient integration systems. Your expertise will directly contribute to enhancing our clients' integration capabilities and driving their digital...
-
Platform Administrator – NextGen SIEM
2 weeks ago
Bengaluru, Karnataka, India ColorTokens Full time US$ 80,000 - US$ 1,20,000 per yearJob Title: Platform Administrator - NextGen SIEM Location: Bangalore (on site) Experience Level: 4 - 8 years About ColorTokens ColorTokens specializes in advanced security solutions designed to safeguard organizations' assets and critical systems from cyber threats. Our flagship product, Xshield Enterprise Microsegmentation platform, empowers...
-
Infometry - Splunk Administrator - Siem/data
2 weeks ago
Bengaluru, India Splunk Administrator Full time**Splunk Administrator**: Role: Splunk Administrator Location: Hyderabad ***: - Install, configure, and update Splunk Enterprise and Splunk Enterprise Security environments in a multi-site environment, following best practices from Splunk Professional Services. - Configure multi-site Search Head clustering and advanced Splunk options like Indexer. -...