SIEM Rule Engineer

1 day ago


Kanpur, Uttar Pradesh, India C3iHub, IIT Kanpur Full time ₹ 5,00,000 - ₹ 15,00,000 per year

Description

The SIEM Rule Engineer is responsible for designing, developing, testing, and tuning detection rules, signatures, and alerts for SIEM, IDS/IPS, and other monitoring platforms. This role focuses on enhancing threat detection capabilities by translating threat intelligence, use cases, and attack patterns into actionable and accurate detections
.

Responsibiliti
es

Rule Engineering & Detection Content Development

  • Develop and maintain correlation rules, signatures, and detection logic in SIEM (e.g., Splunk, ELK, QRadar), IDS/IPS (e.g., Suricata, Snort), and EDR tools (Wazuh).
  • Translate MITRE ATT&CK techniques into detection rules.
  • Tune existing rules to reduce false positives/negatives and improve detection fidelity.
  • Implement YARA, Sigma, or custom detection formats depending on platform needs.
  • Threat Intelligence Integration Collaborate with Threat Intel and Incident Response teams to operationalize IOCs and TTPs.
  • Create enrichment pipelines using threat feeds (STIX/TAXII, MISP, etc.)

SOC Automation & Optimization:

  • Integrate rule alerts with SOAR platforms for response automation.
  • Ensure all rules follow version control and documentation practices (e.g., Git).
  • Conduct regression testing of rules during platform upgrades.

Monitoring & Analytics

  • Continuously monitor and evaluate rule performance using telemetry data.
  • Develop dashboards and reporting for alert metrics, rule health, and detection gaps.

Cross-functional Collaboration

  • Work with blue teams, red teams, compliance, and application owners to refine use cases.
  • Participate in purple teaming exercises and adapt rules for post-attack simulations.

Eligibility

  • Bachelor's or Master's degree in Cybersecurity, Computer Science, or related field.
  • 2–5 years of experience in a SOC, cyber threat detection, or security engineering role.
  • Proficient in writing SIEM rules, Suricata/Snort signatures, or similar detection logic.
  • Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and threat modeling.
  • Hands-on experience with ELK Stack, Splunk, QRadar, or equivalent SIEM.
  • Familiarity with log sources such as Windows Event Logs, Sysmon, Zeek, Suricata, and fire wall logs.

Desired Eligibility

  • Knowledge of scripting (Python, Bash) for custom log parsing or enrichment.
  • Experience with SOAR (e.g., Cortex XSOAR, Splunk SOAR).

Experience with industrial protocols (for OT environments):

  • Modbus, DNP3,S7Comm, etc.
  • Exposure to cloud logging and detection (AWS CloudTrail, Azure Sentinel, etc.).

Certifications: GCIA, GCED, GCTD, Splunk Certified, Elastic Certified Analyst, etc.

Travel

As and when required, across the country for project execution and monitoring, as well as for coordination with geographically distributed teams.

Communication

Submit a cover letter summarising your experience in relevant technologies and software, along with a resume and the Latest passport-size photograph.


  • Lead Engineer

    3 days ago


    Kanpur, Uttar Pradesh, India Technip Energies Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job DescriptionBe part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting-edge solutions to solve real-world energy problems.We are currently seeking aLead Engineer – Process & Technologyto join our Process & Technology team based inNoida & Gurugram, India.About us:Technip Energies is a global...


  • Kanpur, Uttar Pradesh, India Genesis Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    DescriptionBe part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting-edge solutions to solve real-world energy problems.We are currently seeking an Information Security Compliance Specialist, to join our Cybersecurity team based in Noida.About us:Technip Energies is a global technology and...


  • Kanpur, Uttar Pradesh, India Aditya Birla Group Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Job PurposeTo ensure efficient, robust, and sustainable Procurement of Capex items through efficient planning and ensure timely availability of materials in line with quality requirements and at a competitive price, while ensuring compliance with statutory compliance, Safety Compliances as per prescribed policy, procedures & statuary rules.Key Result Areas:4...


  • Kanpur, India Microminder Cyber Security Full time

    Role OverviewWe are looking for a Network Security Engineer with experience in deploying and managing open-source network security platforms. The role involves setting up visibility sensors, handling network traffic capture, and building log pipelines that integrate into SIEM environments. The ideal candidate has worked with packet capture tools, IDS/IPS,...

  • CyberArk Engineer

    2 weeks ago


    Kanpur, India Next Ventures Full time

    Job Opportunity: CyberArk Engineer Role Type:Contract / Permanent / Fixed Term Start Date:Immediate / Within 1 Month Salary:Competitive Day Rate Location:India / Poland / Bulgaria Language Requirements:English Requirements Description We are looking forexperienced CyberArk Engineerswith a minimum of5 years of relevant experiencein Privileged Access...


  • Kanpur, India NTek Software Solutions Full time

    JOB DESCRIPTION : Position : Senior VAPT Consultant Experience : 8+ years Loc : Bengaluru CTC : 35 % Hike on current CTC Job type : Fulltime(Onsite) Job Description We are seeking an experienced and highly skilled Senior VAPT Consultant with 8+ years of hands-on experience in offensive security. The ideal candidate will possess deep technical expertise in...

  • ML Engineer

    2 weeks ago


    Kanpur, India Prospance Inc Full time

    ML Engineer - Cybersecurity AI Platform📍 Location: Remote/Hybrid 💼 Employment Type: Full-time & Part-time opportunities available 🎓 Education: Bachelor's degree required | Master's & PhD students encouraged to apply 🔒 Stealth Mode StartupAbout the OpportunityWe're a well-funded stealth mode startup revolutionizing security operations with...


  • Kanpur, India Insight Global Full time

    Job Title: PAM Solutions Architect – CyberArk SMELocation: India (Fully Remote)Duration: 6 months (with potential extension)Work Arrangement: RemoteYearly Salary: 40-55 lpaOverviewWe are seeking an experienced CyberArk Solutions Architect (PAM SME) to design, implement, and optimize Privileged Access Management (PAM) solutions for a global enterprise...


  • Kanpur, India Dautom Full time

    Job DescriptionSecurity Monitoring and Incident Response Monitor networks and systems for potential security breaches. Investigate and respond to security incidents and anomalies. Conduct forensic analysis to determine the root cause of breaches. System and Network Security Implement and manage firewalls, intrusion detection/prevention systems, and antivirus...

  • Network Engineer

    2 days ago


    Kanpur, India Team Computers Full time

    Network Engineer - L2 Network Engineer - L3Location: Noida Industry: IT Experience Required: 4 - 8 Years Experience for L2 Experience Required: 8 - 12 Years Experience for L3Please share your CVs to "sushmita.rawat@teamcomputers.com" and "vaishno.vibhuti@teamcomputers.com"JD For Network EngineerThe Network & Security Specialist is responsible for the Design,...

  • Sr. Hardware

    2 weeks ago


    Kanpur, India Atlanta Systems Pvt. Ltd. Full time

    Key ResponsibilitiesAs a PCB & Hardware Design Engineer, you’ll be responsible for designing, testing,and optimizing advanced power and control PCBs used in our IoT and embedded productlines.Design multi-layer PCBs for high-performance and power electronic systems using Altium Designer or equivalent tools.Develop and validate analog, digital, and power...

  • Sr. Hardware

    2 weeks ago


    Kanpur, India Atlanta Systems Pvt. Ltd. Full time

    Key ResponsibilitiesAs a PCB & Hardware Design Engineer, you’ll be responsible for designing, testing,and optimizing advanced power and control PCBs used in our IoT and embedded productlines.Design multi-layer PCBs for high-performance and power electronic systems using Altium Designer or equivalent tools.Develop and validate analog, digital, and power...

  • Firewall Engineer

    2 days ago


    Kanpur, India Incedo Inc. Full time

    Key Responsibilities: Provide L2 support via phone, email, and case portal, ensuring timely resolution within defined SLAs and proper escalation of critical issues. Provide support for firewall devices, including setup, upgrades, policy configuration, and troubleshooting. Assist with configuration of NAT, VPNs (IPSec/SSL), firewall rules, routing, and proxy...