CSA SIEM Admin
2 days ago
Job Title: CSA SIEM Admin (Splunk, Sentinel)
Corporate Title: Assistant Vice President
Location: Bangalore, India
Role Description
- The COO Chief Security Office (CSO) is responsible for addressing information security risks to the Deutsche Bank global IT, as a Security Engineer-AVP, you will play a key technical role in our SIEM Operations team within the Global Cyber Security Engineering & Architecture organization.
- You will serve as a technical expert for the platform engineering and provide 24x7x365 support for critical security technologies.
- The role primarily entails hands on technical product design, build & support of multi SIEM platforms Microsoft Sentinel, Chronicle, Splunk. You will be part of a global SIEM Operations Team.
What we'll offer you
As part of our flexible scheme, here are just some of the benefits that you'll enjoy
- Best in class leave policy
- Gender neutral parental leaves
- 100% reimbursement under childcare assistance benefit (gender neutral)
- Sponsorship for Industry relevant certifications and education
- Employee Assistance Program for you and your family members
- Comprehensive Hospitalization Insurance for you and your dependents
- Accident and Term life Insurance
- Complementary Health screening for 35 yrs. and above
Your key responsibilities
- Maintain, upgrade, and troubleshoot issues with SPLUNK (on-pren/cloud) multi-site clusters.
- Design, develop, recommend, and implement Splunk dashboards and alerts in support of the Incident Response team.
- Manage patching and updates of Splunk hosts and/or Splunk application software.
- Monitoring the health and performance of the Splunk environment and troubleshooting any issues that arise.
- Working experience as Splunk Administrator with Cluster Building, Data Ingestion Management, User Role Management Search Configuration and Optimization
- Designs and optimizes Splunk platform architecture for large-scale and distributed deployments.
- Establishes best practices and development standards, and ensures that the team adopts them.
- Configure, manage, and optimize Microsoft Sentinel for efficient threat detection and response.
- Ensure SIEM infrastructure is running optimally, including performance monitoring and issue resolution.
- Regularly update and optimize SIEM policies, rules and configurations based on evolving threats.
- Onboard, configure, and manage data connectors from various log sources, including cloud, on-premises, and hybrid environments.
- Ensure log ingestion health and troubleshoot data collection issues.
- Develop, implement, and fine-tune analytics rules, detection logic, and playbooks in Sentinel.
- Assist SOC and incident response teams with log analysis, threat correlation, and incident investigation.
- Reduce false positives by refining detection rules and optimizing event filtering.
- Implement and enhance automation using Kusto Query Language (KQL), Logic Apps, and Microsoft Defender XDR integrations.
- Maintain SIEM compliance with security policies, industry regulations (e.g., GDPR, NIST, ISO 27001), and best practices.
- Generate reports and dashboards to provide visibility into security posture and SIEM performance.
- Work with SOC, IT, and Cloud Security teams to enhance Sentinel capabilities.
- Document SIEM configurations, detection use cases, and operational procedures.
- Incident & Problem Management, Change & Release Management, Vendor Management, Capacity Management functions for the platform.
- Maintain up-to-date knowledge of technology standards, industry trends, emerging technologies, and cyber security best practices.
- Ensure technical issues are quickly resolved and help implement strategies and solutions to reduce the likelihood of recurrence.
- Passionate about data to drive information-based security analytics.
- Value add - Person in having experience in Cloud Management, Splunk and Chronicle.
Your skills and experience
The candidate must have Engineering Background in Computer Science, Information Technology, Cybersecurity or related field and a minimum of 8+ years of experience with recent experience in Security engineering, system administration, network engineering, software engineering/development with a focus on Cybersecurity.
- 8+ years of IT engineering experience with recent experience in building and managing infrastructure and security platforms.
- 3+ years of Experience implementing, architecting and administering SIEM platforms like Sentinel, Chronicle, Splunk for a large global organization.
- Knowledge of Azure services and data ingestion from those services into SIEM.
- Familiarity with MITRE ATT&CK, cyber threat intelligence and SOC Workflows
- Understanding of SOAR Principles
- Hands on Experience with Microsoft Azure platform, managing various configurations to enable & manage Sentinel.
- Experience developing in XML, Bash, Python, and PowerShell scripts.
- DevOps Engineering experience.(Terraform, SDLC, Actions)
- Independent, self-motivated, proactive approach to problem solving and prevention.
- Excellent written and verbal communication skills.
- Passionate about cyber security and the aptitude to identify and solve security problems.
How we'll support you
- Training and development to help you excel in your career
- Coaching and support from experts in your team
- A culture of continuous learning to aid progression
- A range of flexible benefits that you can tailor to suit your needs
About us and our teams
Please visit our company website for further information:
We strive for a culture in which we are empowered to excel together every day. This includes acting responsibly, thinking commercially, taking initiative and working collaboratively.
Together we share and celebrate the successes of our people. Together we are Deutsche Bank Group.
We welcome applications from all people and promote a positive, fair and inclusive work environment.
-
Security Analyst L3- SIEM
3 days ago
Bangalore, India HR Path Full timeHR Path Group, a global leader in HR consulting, helps clients with their HR transformation projects, covering both human and HRIS (Human Resources Information System) aspects. Our mission is to support our clients at every step of their HR digital transformation with a comprehensive range of services. We support our customers in the transformation of their...
-
Security Analyst L3– SIEM
3 days ago
bangalore, India HR Path Full timeHR Path Group, a global leader in HR consulting, helps clients with their HR transformation projects, covering both human and HRIS (Human Resources Information System) aspects. Our 2,500 employees are located in 28 countries.Our mission is to support our clients at every step of their HR digital transformation with a comprehensive range of services.Advise to...
-
Security Analyst L3- SIEM
3 days ago
bangalore district, India HR Path Full timeHR Path Group, a global leader in HR consulting, helps clients with their HR transformation projects, covering both human and HRIS (Human Resources Information System) aspects. Our 2,500 employees are located in 28 countries. Our mission is to support our clients at every step of their HR digital transformation with a comprehensive range of services. Advise...
-
Security Analyst L3- SIEM
3 days ago
Bangalore, India HR Path Full timeHR Path Group, a global leader in HR consulting, helps clients with their HR transformation projects, covering both human and HRIS (Human Resources Information System) aspects. Our 2,500 employees are located in 28 countries. Our mission is to support our clients at every step of their HR digital transformation with a comprehensive range of services. Advise...
-
Splunk Developer And Admin
1 day ago
Bangalore, Karnataka, India Diverse Lynx Full timeSkill- Splunk Admin Developer and Enterprise securityEducational Backgrounds Degree A bachelor s degree in computer science Information Technology Cybersecurity or a related field is typically required Certifications Splunk ES Administrator or any other SIEM platform certification Detection Engineer Develop and implement detection rules and algorithms to...
-
SIEM Integration Architect
2 days ago
Bangalore - RGA Tech Park, India Unisys Full time ₹ 12,00,000 - ₹ 24,00,000 per yearWhat success looks like in this role: Lead the integration of alarm/data feeds from multiple SIEM platforms (e.g., Splunk, LogRhythm, Securonix) into Microsoft Sentinel.Configure and manage Cribl pipelines to collect, filter, transform, and enrich raw data before forwarding to Sentinel.Design and implement data normalization strategies to ensure consistent...
-
AS400 Admin
6 days ago
bangalore, India People Prime Worldwide Full timeAbout Client: Our client is a global digital solutions and technology consulting company headquartered in Mumbai, India. The company generates annual revenue of over $4.29 billion (₹35,517 crore), reflecting a 4.4% year-over-year growth in USD terms. It has a workforce of around 86,000 professionals operating in more than 40 countries and serves a global...
-
Cyber Security Engineer
2 weeks ago
bangalore, India Tata Consultancy Services Full timeSkill: Splunk Experience Range: 5+ yearsJoining Location: PAN IndiaWe are currently planning to do a Walk-In Interview on 22nd November 2025 at TCS Chennai.WALK IN DATE – 22nd November 2025 (Saturday)WALK IN LOCATION - Chennai/ Bangalore/ HyderabadJob Description:Required SkillsStrong understanding of log management and SIEM concepts.Proficiency in log...
-
Mainframe Storage Admin
3 weeks ago
Bangalore, India Tata Consultancy Services Full timeJD Title: Mainframe Storage Administrator – L3 – 6+ years of experience Experience: 6-9 Years Location: Hyderabad, Bangalore, Chennai Job Description Title of Position: Mainframe or z/OS Storage Admin Summary of key responsibilities Manage BAU (Business as Usual) Service Delivery for Mainframe OS/Storage in a Technical Capacity This is for a pure...
-
Mainframe Storage Admin
3 weeks ago
Bangalore, India Tata Consultancy Services Full timeJD Title: Mainframe Storage Administrator - L3 - 6+ years of experience Experience: 6-9 Years Location: Hyderabad, Bangalore, Chennai Job Description Title of Position: Mainframe or z/OS Storage Admin Summary of key responsibilities Manage BAU (Business as Usual) Service Delivery for Mainframe OS/Storage in a Technical Capacity This is for a pure Technical...