SIEM Rule Engineer

13 hours ago


Kanpur, Uttar Pradesh, India C3iHub, IIT Kanpur Full time ₹ 5,00,000 - ₹ 15,00,000 per year

Description

The SIEM Rule Engineer is responsible for designing, developing, testing, and tuning detection rules, signatures, and alerts for SIEM, IDS/IPS, and other monitoring platforms. This role focuses on enhancing threat detection capabilities by translating threat intelligence, use cases, and attack patterns into actionable and accurate detections
.

Responsibiliti
es

Rule Engineering & Detection Content Development

  • Develop and maintain correlation rules, signatures, and detection logic in SIEM (e.g., Splunk, ELK, QRadar), IDS/IPS (e.g., Suricata, Snort), and EDR tools (Wazuh).
  • Translate MITRE ATT&CK techniques into detection rules.
  • Tune existing rules to reduce false positives/negatives and improve detection fidelity.
  • Implement YARA, Sigma, or custom detection formats depending on platform needs.
  • Threat Intelligence Integration Collaborate with Threat Intel and Incident Response teams to operationalize IOCs and TTPs.
  • Create enrichment pipelines using threat feeds (STIX/TAXII, MISP, etc.)

SOC Automation & Optimization:

  • Integrate rule alerts with SOAR platforms for response automation.
  • Ensure all rules follow version control and documentation practices (e.g., Git).
  • Conduct regression testing of rules during platform upgrades.

Monitoring & Analytics

  • Continuously monitor and evaluate rule performance using telemetry data.
  • Develop dashboards and reporting for alert metrics, rule health, and detection gaps.

Cross-functional Collaboration

  • Work with blue teams, red teams, compliance, and application owners to refine use cases.
  • Participate in purple teaming exercises and adapt rules for post-attack simulations.

Eligibility

  • Bachelor's or Master's degree in Cybersecurity, Computer Science, or related field.
  • 2–5 years of experience in a SOC, cyber threat detection, or security engineering role.
  • Proficient in writing SIEM rules, Suricata/Snort signatures, or similar detection logic.
  • Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and threat modeling.
  • Hands-on experience with ELK Stack, Splunk, QRadar, or equivalent SIEM.
  • Familiarity with log sources such as Windows Event Logs, Sysmon, Zeek, Suricata, and fire wall logs.

Desired Eligibility

  • Knowledge of scripting (Python, Bash) for custom log parsing or enrichment.
  • Experience with SOAR (e.g., Cortex XSOAR, Splunk SOAR).

Experience with industrial protocols (for OT environments):

  • Modbus, DNP3,S7Comm, etc.
  • Exposure to cloud logging and detection (AWS CloudTrail, Azure Sentinel, etc.).

Certifications: GCIA, GCED, GCTD, Splunk Certified, Elastic Certified Analyst, etc.

Travel

As and when required, across the country for project execution and monitoring, as well as for coordination with geographically distributed teams.

Communication

Submit a cover letter summarising your experience in relevant technologies and software, along with a resume and the Latest passport-size photograph.


  • Lead Engineer

    3 days ago


    Kanpur, Uttar Pradesh, India Technip Energies Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Job DescriptionBe part of the solution at Technip Energies and embark on a one-of-a-kind journey. You will be helping to develop cutting-edge solutions to solve real-world energy problems.We are currently seeking aLead Engineer – Process & Technologyto join our Process & Technology team based inNoida & Gurugram, India.About us:Technip Energies is a global...

  • Project Manager

    2 weeks ago


    Kanpur, Uttar Pradesh, India Electronics Club Full time ₹ 2,400 per year

    ADVERTISEMENTDepartment of Materials Science and EngineeringAdvertisement Number: P.Rect./R&D/2025/186Applications are invited for the post of Project Manager (one) in a DRDO Industry-Academia Centre of Excellence at Indian Institute of Technology Kanpur.Position: Project Manager (ONE)Minimum Qualification: Post graduate degree + 8 years of relevant...


  • Kanpur, India Microminder Cyber Security Full time

    Role OverviewWe are looking for a Network Security Engineer with experience in deploying and managing open-source network security platforms. The role involves setting up visibility sensors, handling network traffic capture, and building log pipelines that integrate into SIEM environments. The ideal candidate has worked with packet capture tools, IDS/IPS,...


  • Kanpur, India NTek Software Solutions Full time

    JOB DESCRIPTION : Position : Senior VAPT Consultant Experience : 8+ years Loc : Bengaluru CTC : 35 % Hike on current CTC Job type : Fulltime(Onsite) Job Description We are seeking an experienced and highly skilled Senior VAPT Consultant with 8+ years of hands-on experience in offensive security. The ideal candidate will possess deep technical expertise in...


  • Kanpur, Uttar Pradesh, India AXIS CONSULTANTS Full time

    **Job Description-** Qualification: - Msc Environment or M.Tech Environmental Engineering Work Experience: - 2-3 years in Environmental/Pollution Consulting Firm **(mandatory)** Work Profile: - Assessment and advisory services to clients on matters pertaining to the management of environmental issues. - Ensuring that revised environmental policies and...


  • Kanpur, Uttar Pradesh, India Weekday AI Full time

    This role is for one of Weekday s clients Salary range Rs 3000000 - Rs 4000000 ie INR 30-40 LPA Min Experience 15 years Location Gurgaon JobType full-time Requirements We are hiring an experienced and dynamic Facility Director for a reputed hospital in Kanpur This leadership position is ideal for a seasoned professional with a minimum of 15 years...