T

SIEM engineer

Tata Consultancy Services · Indore, Madhya Pradesh, India

3–9 yrs experiencefull_timePosted 1w ago

Job description

**Location: Indore/ Delhi** **#Role Summary:** We are looking for an experienced SIEM Engineer to join our SOC team. The role involves managing and optimizing SIEM platforms (primarily **Microsoft Sentinel** , Splunk/Elastic), developing detection content, automating workflows, and supporting threat hunting and incident response. **#Key Responsibilities:** - Onboard and normalize log sources (cloud, endpoint, network, SaaS). - Develop and tune detection rules (KQL/ SPL) mapped to MITRE ATT&CK. - Build dashboards, health checks, and KPIs. - Implement SOAR automation (Sentinel Playbooks, Logic Apps). - Support threat hunting and assist in incident investigations. - Maintain SIEM performance, cost optimization, and compliance. **#Required Skills:** - 5–8 years in SOC/Threat Detection/Incident Response/SIEM engineering roles. - Strong expertise in Microsoft Sentinel (KQL, SPL, analytics rules, hunting, playbooks). - Hands-on with at least one other SIEM (Splunk, Sentinelone, Elastic). - Knowledge of MITRE ATT&CK, detection engineering, and log analysis. - Scripting in PowerShell/Python for automation. - Familiarity with EDR, IAM, firewall, and cloud security logs. - Must have SIEM solution implementation experience. **#Preferred Certifications:** - SC-200 or AZ-500 - Splunk