SIEM Engineer
6 days ago
Cyber
Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights to help our clients navigate the ever-changing threat landscape. Through powerful insights and managed services that simplify complexity, we enable businesses to operate with resilience, grow with confidence, and proactively manage to secure achievements.
Cyber Operate
We help organizations create a cyber minded culture, reimagine risk to uncover strategic opportunities, and become faster, more innovative, and more resilient in the face of ever-changing threats. As organizations are called upon to align their priorities and to drive core business objectives and reduce risk, our cyber and strategic risk management team helps clients focus on enterprise level risks through a wider lens.
Deloittes Detect & Respond (D&R) aims to combine sophisticated technologies and human intelligence to help the clients monitor, detect, investigate, and respond to known and unknown attacks. We help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. Detect and Respond team delivers service to clients through following key areas:
- Threat detection and response
- Attack surface management
- Threat Intelligence
- Threat Hunting
- Data Protection
Work you'll do
- As a SIEM Engineer (SPLUNK, Sentinel, Chronicle) you will be managing and providing SIEM health and operational support, including supporting to architecture changes, tool deployments and advanced content development.
- Perform SIEM configuration management, and troubleshooting, addressing complex issues and day to day operations management
- Onboard security log data sources and develop new and custom parsers
- Perform SIEM architecture assessments, content baseline assessment and design reviews
- Deliver SIEM advisory support and education to other SOC and technology management personnel
- Help define, implement and monitor key risk indicators and key performance indicators (KRIs/KPIs)
- Keep abreast of latest IT security, regulatory and compliance trends to support various risk and data model
- Security information and event management (SIEM) Use Case content functional and quality testing
- Developing actionable use cases to detect, triage, investigate and remediate based on latest threat actor trends, including actual technical implementation of parsing log sources creating, validating and testing alerting queries to reduce false positives.
- Enhancing and documenting existing SOC processes to increase centralized visibility in order to identify suspicious activity to reduce the mean time to detect and respond to cyber threats.
- Assist in Use Case Roadmap development and update Use Cases in Use Case Repository
- Coordinate with Content Engineers to support advanced Use Case development (Use Case from Roadmap as well as hunting related Use Cases)
- Help maintain content development/deployment baseline across clients based on the maturity of the client environment as well as the latest trends in security
- Review system security plans, network diagrams, and vulnerability and patching requirements
- Develop scripts to simplify data collection and automate data onboarding tasks
- Provide 24/7 on-call support (as needed)
- Coordinate with various technical groups and attend in-person client meetings
- Build relationships with client counterpart (i.e. Client Lead Security Engineer)
Required skills
- Bachelor's degree is required. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.
- 5+ years' experience in security information and/or technology engineering support.
- Certified Information Systems Security Professional (CISSP), Certification in Certified Intrusion Analyst (GIAC), Continuous Monitoring (GMON), Certified Ethical Hacker (CEH) or equivalent
- Extensive experience in security technologies such as: Security information and event management (SIEM), IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint detection and response (EDR), Anti-Virus, Sandboxing, network- and host- based firewalls, Threat Intelligence, Penetration Testing, etc.
- Knowledge of Advanced Persistent Threats (APT) tactics, technics and procedures
- Understanding of possible attack activities such as network probing/ scanning, DDOS, malicious code activity, etc
- Understanding of common network infrastructure devices such as routers and switches
- Understanding of basic networking protocols such as TCP/IP, DNS, HTTP
- Detailed knowledge in system security architecture and security solutions
Preferred skills
- Experience interpreting, searching, and manipulating data within enterprise logging solutions (e.g. SIEM, IT Service Management (ITSM) tools, workflow, and automation)
- Ethical Hacking and Information Security certifications such as OSCP, CEH, CISSP, SANS etc.
- SIEM certifications such as Splunk Architecture, HP ArcSight, IBM QRadar certified, etc.
- Certifications; CISSP, CISA, CISM, GCIH, GMON, GCDA, GPEN, GCFA, GCTI
- Excellent interpersonal and organizational skills
- Excellent oral and written communication skills
- Strong analytical and problem-solving skills
- Self-motivated to improve knowledge and skills
- A strong desire to understand the what as well as the why and the how of security incidents
Qualification
- Bachelor's degree is required. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.
-
Sr. SOC Engineer – SIEM Engineering
2 weeks ago
Chennai, Tamil Nadu, India qpact Full time ₹ 4,20,000 - ₹ 13,50,000 per yearSr. SOC Engineer – SIEM EngineeringExperience: 4 years to 9 yearsMax Budget: 4 to 7 Years - 10 LPA7 to 9 years – 13.5 LPAJob Description:•Configure, deploy, and maintain the organization's SIEM platform to ensure optimal performance and functionality.•Develop and customize SIEM rules, filters, and alerts to meet specific security monitoring and...
-
SIEM Analyst
1 week ago
Chennai, Tamil Nadu, India MNR Solutions Pvt. Ltd. Full time ₹ 2,00,000 - ₹ 12,00,000 per yearDescription : Job Summary : We are looking for a SIEM Engineer / Analyst (L1/L2/L3) to monitor, analyze, and respond to security events using SIEM tools. The candidate will help detect threats, perform incident triage, and support security operations to protect the organizations digital assets. Key Responsibilities : L1 (Entry-Level / Junior SIEM...
-
Principal Engineer
2 weeks ago
Bengaluru, India Optiv Full timeDescription :Our Principal engineers are skilled technical and consultative resources expected to be strong in both technical and soft skills.A principal engineer must be driven and proactive with the ability to problem-solve, communicate, participate in diverse project teams from a technical perspective, and interface effectively with customers, vendor...
-
SIEM Engineer
4 days ago
APAC - India - Bengaluru - Sunriver Autodesk Full time ₹ 12,00,000 - ₹ 24,00,000 per yearJob Requisition ID # 25WD92686Position OverviewAutodesk is seeking a highly skilled SIEM Engineer to manage and enhance our SIEM platform. This role involves working closely with the SOC, Detection Engineers, Threat Hunters, Security Logging, and SOAR teams to develop, evolve, and fine-tune detections, alerts, and other SIEM configurations to protect...
-
SIEM Admin
3 days ago
Bengaluru, Karnataka, India Tata Consultancy Services (TCS) Full time ₹ 12,00,000 - ₹ 36,00,000 per yearSr. SIEM admin with minimum 5+ yrs of exp,strong knowledge in Custom parser developmentThreat detection use-case designing, implementation and fine-tuning,create rules/dashboards for compliance and audit requirements.Strong understanding of security incident management, malware management and vulnerability management processesWorking knowledge of the...
-
Lead SIEM Engineer
7 days ago
Hyderabad, India Antal International Full timeOur client — a leading healthcare provider — is looking for a SIEM / EDR Specialist (8–13 years) to design, deploy, and implement enterprise-level security solutions that safeguard critical data and operations.Location : Hyderabad (Onsite)Experience : 8–13 yearsIndustry : HealthcareKey Responsibilities:Architect, deploy, and manage SIEM and EDR...
-
Lead SIEM Engineer
4 days ago
Hyderabad, India Antal International Full timeOur client — a leading healthcare provider — is looking for a SIEM / EDR Specialist (8–13 years) to design, deploy, and implement enterprise-level security solutions that safeguard critical data and operations.Location : Hyderabad (Onsite)Experience : 8–13 yearsIndustry : HealthcareKey Responsibilities:Architect, deploy, and manage SIEM and EDR...
-
Lead SIEM Engineer
7 days ago
hyderabad, India Antal International Full timeOur client — a leading healthcare provider — is looking for a SIEM / EDR Specialist (8–13 years) to design, deploy, and implement enterprise-level security solutions that safeguard critical data and operations.Location: Hyderabad (Onsite)Experience: 8–13 yearsIndustry: HealthcareKey Responsibilities:Architect, deploy, and manage SIEM and EDR...
-
Lead SIEM Engineer
7 days ago
Hyderabad, India Antal International Full timeOur client — a leading healthcare provider — is looking for a SIEM / EDR Specialist (8–13 years) to design, deploy, and implement enterprise-level security solutions that safeguard critical data and operations.Location: Hyderabad (Onsite)Experience: 8–13 yearsIndustry: HealthcareKey Responsibilities:Architect, deploy, and manage SIEM and EDR...
-
Lead SIEM Engineer
5 days ago
Hyderabad, India Antal International Full timeOur client — a leading healthcare provider — is looking for a SIEM / EDR Specialist (8–13 years) to design, deploy, and implement enterprise-level security solutions that safeguard critical data and operations. Location : Hyderabad (Onsite) Experience : 8–13 years Industry : Healthcare Key Responsibilities: Architect, deploy, and manage SIEM and EDR...