Associate - Cybersecurity
7 hours ago
Role Summary:
We are looking for a technically strong and process-driven SIEM Integration & Engineering Specialist with proven experience in Microsoft Sentinel to lead and execute end-to-end integration, onboarding, log parsing, transformation, and ingestion optimization activities. You will own the engineering lifecycle of log source integration, tuning, troubleshooting ingestion issues, and developing reusable automation/SOPs to support multiple enterprise and MSSP customers.
Key Responsibilities: Integration & Configuration
Create and maintain onboarding checklists for all new log sources: log size estimation, ingestion strategy, placement logic (Syslog/CommonSecurityLog/CustomLog), best onboarding method (agent, API, etc.).
Evaluate and implement native vs custom ingestion using REST APIs, syslog, CEF, Syslog-NG, and event hubs.
Manage Data Collection Rules (DCRs) for structured and unstructured data including transformations, filters, multi-line handling, and custom table mapping.
Author SOPs and "How-to" documentation for custom log normalization, transformation logic, and DCR limitations.
Recommend and justify table selection strategy (e.g., CommonSecurityLog vs. CustomLog) based on customer needs and Sentinel performance.
Ingestion Optimization & Tuning
Identify and resolve log duplication issues using correlation, diagnostic settings, and parsing analysis.
Choose between agent-based and agentless ingestion strategies; document troubleshooting methods and share reusable configurations.
Design ingestion pipelines considering performance throttling, throughput optimization, and pre-ingestion routing (like log routers, collectors, proxies).
Collaborate with customers to align ingestion design with retention policies and data costs.
Health Monitoring & Troubleshooting
Develop and maintain log rotation configurations/scripts for Linux and Windows sources, including detection and remediation of rotation issues.
Create scheduled health checks, KQL rules, and workbooks to detect connector failures, latency, heartbeat gaps, and log drop-offs.
Document common ingestion failure patterns (encoding errors, firewall/network issues, schema mismatches) with precise troubleshooting playbooks.
Maintain playbooks for character encoding issues (UTF-8, BOM) and solutions for encrypted log payloads or malformed syslog headers.
Forwarding & Collection Methods
Lead Windows Event Forwarding (WEF) implementation via GPO with enhanced configurations, filtering, and troubleshooting best practices.
Configure and tune Sysmon, Syslog-NG, Rsyslog, and Logstash for Linux and application logs; implement JDBC or file-based DB integrations.
Create reusable templates for schema mapping and log parsing pipelines for non-standard applications and tools.
Scripting & Automation
Build PowerShell/Bash scripts to automate onboarding of frequently used log sources.
Maintain or create ARM/Bicep templates for Sentinel infrastructure provisioning, including DCRs, diagnostic settings, and analytics rules.
Script or pipeline complex log transformations, parsing pipelines, and even alert tuning workflows (e.g., via Logic Apps).
Access Management & Security
Define and manage RBAC roles for Sentinel, data source connectors, and ingestion tools.
Implement Managed Identity-based ingestion for secure connections (e.g., Azure Function Apps, Logstash, REST APIs).
Audit and document access control, permission requirements, and secure token-based configurations used for custom integrations.
Must-Have Skills:
3+ years of hands-on experience with Microsoft Sentinel including DCR, KQL, and ingestion pipeline management.
Solid understanding of Syslog, CEF, Windows Event Forwarding, REST APIs, and custom data connectors.
Expertise in KQL, JSON, PowerShell/Bash, and parsing logic for complex logs.
Proven experience developing health monitoring solutions and troubleshooting data latency, connector failures, and ingestion issues.
Strong experience in SOP development, documentation, and reusable automation.
Familiarity with data transformation logic, log source prioritization, and cost management strategies in Sentinel.
Ability to work closely with security teams, cloud architects, and customer IT teams to implement best practices.
Nice-to-Have Skills:
Experience with Logstash, Syslog-NG, Rsyslog, and JDBC log integrations.
Prior work with Managed Sentinel deployments or other MSSP environments.
Familiarity with SOAR automation (Logic Apps) and integrating Sentinel with external alerting platforms.
Knowledge of Microsoft Defender XDR, Azure Security Center, or other Microsoft Security solutions.
Exposure to compliance-driven onboarding (HIPAA, PCI-DSS, ISO for regulated customers.
Soft Skills & Approach:
Process-oriented mindset with strong documentation habits.
Ability to work independently while handling multiple log source requests.
Troubleshooting-first approach with a mindset of identifying root cause, not just symptoms.
Strong communication skills for knowledge transfer and training of L1/L2 teams.
Deliverables/Artifacts the Role Will Own:
Master log source onboarding guidebook
SOP library for custom and native integrations
Collection of scripts and templates (DCR, KQL rules, health monitors, log rotation)
Workbook for ingestion health monitoring
Repository of common failure scenarios and fix playbooks
-
Senior Associate – Cybersecurity
2 days ago
Mumbai, Maharashtra, India Ankura Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAnkura is a team of excellence founded on innovation and growth.Ankura's Cyber & Privacy practice is part of the Data & Technology business group - one of six practices dedicated to client delivery services across the firm.Ankura Consulting India is part of Ankura Global network which is present across more than 35 countries. In India, Globally, Ankura is...
-
Associate - Cybersecurity
3 days ago
Mumbai, Maharashtra, India Inspira Full time ₹ 8,00,000 - ₹ 24,00,000 per yearDescriptionJob Title: SOAR Engineer – Microsoft Sentinel & Automation DevelopmentJob Description:We are looking for a dynamic SOAR Engineer to join our cybersecurity team, specializing in automation and orchestration using Microsoft Sentinel. The ideal candidate will have deep expertise in developing Logic App playbooks and hands-on experience with Power...
-
Mumbai, Maharashtra, India Ares Management Full time ₹ 12,00,000 - ₹ 36,00,000 per yearOver the last 20 years, Ares' success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming,...
-
Mumbai, Maharashtra, India DBS Bank Full time ₹ 12,00,000 - ₹ 24,00,000 per yearJob Summary: The Cybersecurity Regulatory and Compliance Officer is responsible for ensuring the organization's cybersecurity practices comply with applicable laws, regulations, frameworks, and internal policies. This role bridges the gap between cybersecurity operations and legal/regulatory obligations, ensuring the organization maintains a robust,...
-
Mumbai, Maharashtra, India DBS Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Summary:The Cybersecurity Regulatory and Compliance Officer is responsible for ensuring the organization's cybersecurity practices comply with applicable laws, regulations, frameworks, and internal policies. This role bridges the gap between cybersecurity operations and legal/regulatory obligations, ensuring the organization maintains a robust, compliant...
-
Cyber Security Associate
6 days ago
Mumbai, Maharashtra, India ServQual Full time ₹ 12,00,000 - ₹ 36,00,000 per yearLocation: Mumbai, IndiaCompany: ServQual LimitedEmployment Type: Full-time, OnsiteServQual is a global cybersecurity and technology company with offices in the UK, USA, and India, operating on a "Follow-the-Sun" model. We specialize in simplifying cybersecurity and privacy compliance through our AI-driven GRC platform – SUSAN (ServQual Unicorn Security...
-
Senior Associate
2 weeks ago
Mumbai, Maharashtra, India BNP Paribas Full time ₹ 12,00,000 - ₹ 24,00,000 per yearAbout BNP Paribas India SolutionsEstablished in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union's leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and...
-
Associate - Cybersecurity
7 hours ago
Mumbai, Maharashtra, India Inspira Full time ₹ 40,00,000 - ₹ 1,20,00,000 per yearDescriptionAutomate incident response by designing, developing, and maintaining SOAR playbooks and workflows to streamline threat detection and mitigation Integrate security tools (SIEM, EDR, threat‑intel platforms) with the SOAR solution to enhance visibility and orchestration Collaborate with SOC and security engineering teams to identify manual...
-
Cyber Security Analyst
2 days ago
Mumbai, Maharashtra, India Vaamoz Online Full time ₹ 12,00,000 - ₹ 36,00,000 per yearCyber Security Analyst Role Our organization is seeking a Cyber Security Analyst to evaluate and secure our computer network. You will be responsible for introducing cybersecurity best practices, conducting risk and vulnerability assessments, ensuring compliance with security protocols, and protecting sensitive data, information systems, and databases. The...
-
Fund Servicing Operations Associate
2 days ago
Mumbai, Maharashtra, India JPMorganChase Full time ₹ 5,00,000 - ₹ 10,00,000 per yearDescription Join JPMorganChase as a Fund Servicing Associate II and be at the forefront of enhancing our operational services in fund accounting and administration. This role offers a unique opportunity for career growth and skill development, as you collaborate with a dynamic team and contribute to impactful solutions. Experience the benefits of being part...