SIEM Engineer

6 days ago


Bengaluru Chennai Hyderabad, India Deloitte Consulting Full time ₹ 6,00,000 - ₹ 12,00,000 per year

Cyber

Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful insights to help our clients navigate the ever-changing threat landscape. Through powerful insights and managed services that simplify complexity, we enable businesses to operate with resilience, grow with confidence, and proactively manage to secure achievements.

Cyber Operate

We help organizations create a cyber minded culture, reimagine risk to uncover strategic opportunities, and become faster, more innovative, and more resilient in the face of ever-changing threats. As organizations are called upon to align their priorities and to drive core business objectives and reduce risk, our cyber and strategic risk management team helps clients focus on enterprise level risks through a wider lens.

Deloittes Detect & Respond (D&R) aims to combine sophisticated technologies and human intelligence to help the clients monitor, detect, investigate, and respond to known and unknown attacks. We help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. Detect and Respond team delivers service to clients through following key areas:

  • Threat detection and response
  • Attack surface management
  • Threat Intelligence
  • Threat Hunting
  • Data Protection

Work you'll do

  • As a SIEM Engineer (SPLUNK, Sentinel, Chronicle) you will be managing and providing SIEM health and operational support, including supporting to architecture changes, tool deployments and advanced content development.
  • Perform SIEM configuration management, and troubleshooting, addressing complex issues and day to day operations management
  • Onboard security log data sources and develop new and custom parsers
  • Perform SIEM architecture assessments, content baseline assessment and design reviews
  • Deliver SIEM advisory support and education to other SOC and technology management personnel
  • Help define, implement and monitor key risk indicators and key performance indicators (KRIs/KPIs)
  • Keep abreast of latest IT security, regulatory and compliance trends to support various risk and data model
  • Security information and event management (SIEM) Use Case content functional and quality testing
  • Developing actionable use cases to detect, triage, investigate and remediate based on latest threat actor trends, including actual technical implementation of parsing log sources creating, validating and testing alerting queries to reduce false positives.
  • Enhancing and documenting existing SOC processes to increase centralized visibility in order to identify suspicious activity to reduce the mean time to detect and respond to cyber threats.
  • Assist in Use Case Roadmap development and update Use Cases in Use Case Repository
  • Coordinate with Content Engineers to support advanced Use Case development (Use Case from Roadmap as well as hunting related Use Cases)
  • Help maintain content development/deployment baseline across clients based on the maturity of the client environment as well as the latest trends in security
  • Review system security plans, network diagrams, and vulnerability and patching requirements
  • Develop scripts to simplify data collection and automate data onboarding tasks
  • Provide 24/7 on-call support (as needed)
  • Coordinate with various technical groups and attend in-person client meetings
  • Build relationships with client counterpart (i.e. Client Lead Security Engineer)

Required skills

  • Bachelor's degree is required. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.
  • 5+ years' experience in security information and/or technology engineering support.
  • Certified Information Systems Security Professional (CISSP), Certification in Certified Intrusion Analyst (GIAC), Continuous Monitoring (GMON), Certified Ethical Hacker (CEH) or equivalent
  • Extensive experience in security technologies such as: Security information and event management (SIEM), IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint detection and response (EDR), Anti-Virus, Sandboxing, network- and host- based firewalls, Threat Intelligence, Penetration Testing, etc.
  • Knowledge of Advanced Persistent Threats (APT) tactics, technics and procedures
  • Understanding of possible attack activities such as network probing/ scanning, DDOS, malicious code activity, etc
  • Understanding of common network infrastructure devices such as routers and switches
  • Understanding of basic networking protocols such as TCP/IP, DNS, HTTP
  • Detailed knowledge in system security architecture and security solutions

Preferred skills

  • Experience interpreting, searching, and manipulating data within enterprise logging solutions (e.g. SIEM, IT Service Management (ITSM) tools, workflow, and automation)
  • Ethical Hacking and Information Security certifications such as OSCP, CEH, CISSP, SANS etc.
  • SIEM certifications such as Splunk Architecture, HP ArcSight, IBM QRadar certified, etc.
  • Certifications; CISSP, CISA, CISM, GCIH, GMON, GCDA, GPEN, GCFA, GCTI
  • Excellent interpersonal and organizational skills
  • Excellent oral and written communication skills
  • Strong analytical and problem-solving skills
  • Self-motivated to improve knowledge and skills
  • A strong desire to understand the what as well as the why and the how of security incidents

Qualification

  • Bachelor's degree is required. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.

  • SIEM Engineer

    3 weeks ago


    Hyderabad, India Anicalls (Pty) Ltd Full time

    Candidate should be able to: Drive multiple simultaneous workstreams; manage schedules, risks, and issues with effective communication to the team, to senior management, and company executives. Research and keep up to date on threat actors and new TTP. Write incident reports and deliver presentations to key business partners as well as help define...


  • Chennai, Tamil Nadu, India qpact Full time ₹ 4,20,000 - ₹ 13,50,000 per year

    Sr. SOC Engineer – SIEM EngineeringExperience: 4 years to 9 yearsMax Budget: 4 to 7 Years - 10 LPA7 to 9 years – 13.5 LPAJob Description:•Configure, deploy, and maintain the organization's SIEM platform to ensure optimal performance and functionality.•Develop and customize SIEM rules, filters, and alerts to meet specific security monitoring and...

  • SIEM Analyst

    1 week ago


    Chennai, Tamil Nadu, India MNR Solutions Pvt. Ltd. Full time ₹ 2,00,000 - ₹ 12,00,000 per year

    Description : Job Summary : We are looking for a SIEM Engineer / Analyst (L1/L2/L3) to monitor, analyze, and respond to security events using SIEM tools. The candidate will help detect threats, perform incident triage, and support security operations to protect the organizations digital assets. Key Responsibilities : L1 (Entry-Level / Junior SIEM...

  • SIEM Lead

    4 weeks ago


    Bengaluru, India Hiret Consulting Full time

    We are seeking an experienced SIEM & Security Analytics Engineer (SIEM Lead) to design, develop, and enhance our detection capabilities across multiple SIEM platforms. This role involves building advanced correlation rules, use cases, and SOAR playbooks while integrating new log sources from both on-premises and cloud environments. The SIEM Lead will also...

  • SIEM Lead

    4 weeks ago


    Bengaluru, India Hiret Consulting Full time

    We are seeking an experienced SIEM & Security Analytics Engineer (SIEM Lead) to design, develop, and enhance our detection capabilities across multiple SIEM platforms. This role involves building advanced correlation rules, use cases, and SOAR playbooks while integrating new log sources from both on-premises and cloud environments. The SIEM Lead will also...

  • SIEM Lead

    4 weeks ago


    Bengaluru, India Hiret Consulting Full time

    We are seeking an experienced SIEM & Security Analytics Engineer (SIEM Lead) to design, develop, and enhance our detection capabilities across multiple SIEM platforms. This role involves building advanced correlation rules, use cases, and SOAR playbooks while integrating new log sources from both on-premises and cloud environments. The SIEM Lead will also...


  • Hyderabad, India Alignity Solutions Full time

    Do you love a career where you Experience , Grow & Contribute at  the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you. Learn how we are redefining the meaning of work , and be a part of the team raved by Clients, Job-seekers and Employees. Jobseeker Video Testimonials ...


  • Hyderabad, India Alignity Solutions Full time

    Do you love a career where you Experience , Grow & Contribute at  the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you. Learn how we are redefining the meaning of work , and be a part of the team raved by Clients, Job-seekers and Employees. Jobseeker Video...

  • SIEM Lead

    4 weeks ago


    Bengaluru, India Hiret Consulting Full time

    We are seeking an experienced SIEM & Security Analytics Engineer (SIEM Lead) to design, develop, and enhance our detection capabilities across multiple SIEM platforms. This role involves building advanced correlation rules, use cases, and SOAR playbooks while integrating new log sources from both on-premises and cloud environments. The SIEM Lead will also...

  • SIEM Lead

    4 weeks ago


    Bengaluru, India Hiret Consulting Full time

    We are seeking an experienced SIEM & Security Analytics Engineer (SIEM Lead) to design, develop, and enhance our detection capabilities across multiple SIEM platforms. This role involves building advanced correlation rules, use cases, and SOAR playbooks while integrating new log sources from both on-premises and cloud environments. The SIEM Lead will also...