Detection Engineer L3

Capgemini

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Capgemini in Bengaluru is seeking a Detection Engineer to design, develop, test, and continuously improve threat detection capabilities across enterprise environments, including cloud, identity, endpoint, email, SaaS, OT, and data platforms. You will leverage Microsoft security technologies, threat intelligence, and threat-informed defense methodologies to build scalable, high-fidelity detection content.

You will collaborate with SOC, Data Onboarding, Automation, Cloud, Identity, and

Qualifications

  • Hands-on experience with Microsoft Sentinel and Defender XDR.
  • Proficient in KQL and scripting (Python, PowerShell).
  • Expert at threat-informed defense and MITRE ATT&CK mapping.
  • Experience with detection-as-code and CI/CD pipelines.

Responsibilities

  • Design, develop, test, and improve threat detections across enterprise environments.
  • Translate intelligence and incident findings into detection requirements and roadmaps.
  • Validate detections via attack simulations and telemetry, minimizing false positives.
  • Collaborate with SOC, Cloud, Identity, and Infra teams for telemetry readiness and operational handoff.
  • Maintain detection-as-code practices, CI/CD pipelines, and documentation.

Skills

Microsoft Sentinel
Defender XDR
Azure Data Explorer
KQL (Kusto)
Python
PowerShell
Threat hunting
Detection engineering

Tools

Sigma/YAML content tooling

Job description

As a Detection Engineer at Capgemini, you will be responsible for designing, developing, testing, and continuously improving threat detection capabilities across enterprise environments, including cloud, identity, endpoint, email, SaaS, OT, and data platforms. You will leverage Microsoft security technologies, threat intelligence, and threat-informed defense methodologies to build scalable, actionable, and high-fidelity detection content that strengthens the organization's cyber defense posture.

  • Design, develop, tune, and maintain detection use cases, analytics rules, correlation logic, hunting queries, dashboards, watchlists, and behavioral analytics within Microsoft Sentinel, Defender XDR, Azure Data Explorer, and related platforms.
  • Translate threat intelligence, incident findings, attack emulation results, vulnerability insights, cloud/SaaS risks, and business priorities into effective detection requirements and detection engineering roadmaps.
  • Validate detections through attack simulation, synthetic telemetry, threat emulation frameworks, historical data analysis, and operational testing while minimizing false positives through tuning and enrichment.
  • Collaborate with SOC, Data Onboarding, Automation, Cloud, Identity, and Infrastructure teams to ensure telemetry readiness, detection effectiveness, SOAR integration, and successful operational handoff.
  • Maintain detection-as-code practices, CI/CD pipelines, testing frameworks, documentation, MITRE ATT&CK mapping, threat hunting outcomes, and continuous improvement processes for detection lifecycle management.
Your profile
  • Hands-on experience in Microsoft Sentinel, Defender XDR, Azure Data Explorer, and advanced threat hunting across enterprise environments.
  • Expert-level proficiency in Kusto Query Language (KQL) with strong Python and PowerShell scripting skills for detection engineering, automation, and attack simulation.
  • Strong understanding of MITRE ATT&CK, threat-informed defense, detection engineering, SIEM/XDR architectures, correlation logic, entity mapping, and alert enrichment.
  • Experience with detection-as-code, content lifecycle management, CI/CD pipelines, Git, testing automation, Sigma/YAML content development, and security analytics engineering.
  • Deep knowledge of Windows, Linux, Active Directory, Entra ID, Azure, Microsoft 365, cloud security, SaaS platforms, endpoint security, network security, OT/industrial telemetry, threat intelligence, and security data science tools such as Databricks, MSTICPy, and Jupyter notebooks.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Engineer L3
SIEM Engineer L3

Capgemini • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Detection Engineer
Detection Engineer

Terralogic • Bengaluru

On-site
INR 1,200,000 - 1,600,000
Sr. Consultant
Sr. Consultant

Tribastion Technologies Pvt. Ltd. • India

On-site
INR 1,000,000 - 1,500,000
SIEM & Detection Engineering Specialist
SIEM & Detection Engineering Specialist

Lonvec Technologies Private Limited • Bengaluru

Hybrid
INR 1,800,000 - 2,600,000
Cyber Security Engineer
Cyber Security Engineer

Sapphire Software Solutions Inc • India

Remote
INR 1,800,000 - 2,800,000
Azure Sentinel
Azure Sentinel

Cloudxtreme • Hyderabad, Chennai District, Bengaluru

On-site
INR 4,500,000 - 6,500,000
AI Detection Engineer - SOC Analyst IV
AI Detection Engineer - SOC Analyst IV

Ten Eleven Ventures • Bengaluru

On-site
INR 2,000,000 - 3,000,000
MS Sentinel and EDR Specialist, SOC L3 (SME)
MS Sentinel and EDR Specialist, SOC L3 (SME)

HypTechie • Faridabad District

On-site
INR 1,200,000 - 1,800,000
Cloud Security Engineer
Cloud Security Engineer

ERM Placement Services • Kolkata District

On-site
INR 900,000 - 1,700,000
Cloud Security Engineer
Cloud Security Engineer

ERM Placement Services • Lucknow

On-site
INR 900,000 - 1,500,000