Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)

IT MNC

Karnataka

On-site

INR 1,500,000 - 2,000,000

Full time

8 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

IT MNC in Bengaluru invites an experienced SOC L3 professional with Elastic SIEM & SOAR expertise to lead investigations and optimize security operations. You will design and tune Elastic Security deployments, develop playbooks, mentor L1/L2 analysts, and coordinate incident response across cloud and on-prem environments.

You will collaborate with cross-functional teams to improve detection coverage and drive SOC modernization efforts.

Qualifications

  • Hands-on experience with Elastic SIEM and Elastic Security.
  • Experience with SOAR implementation and automation orchestration.
  • Experience with multiple SIEM platforms (MS Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic or equivalent).
  • Strong understanding of Windows, Linux, AD, Azure, AWS, networking and cloud security.
  • Scripting in Python/PowerShell/Bash for automation.

Responsibilities

  • Lead L3 investigations for complex security incidents and advanced threats.
  • Design, implement, and optimize Elastic SIEM and Elastic Security deployments.
  • Develop and maintain SOAR playbooks, automation workflows, and integrations.
  • Build and tune detection rules, correlation logic, dashboards, alerts and threat hunting content.
  • Support end-to-end SIEM implementation including onboarding log sources, parsing, normalization, and data pipelines.
  • Perform threat hunting, malware analysis, and root cause investigations.
  • Provide guidance to L1/L2 analysts and lead incident response activities.
  • Integrate threat intelligence feeds and improve detection maturity.
  • Conduct use case development, validation, and security monitoring enhancements.
  • Participate in SOC transformation, SIEM migrations, and platform evaluations.

Skills

SOC operations
Incident response
Threat hunting
Mentoring
Client-facing communication

Tools

Elastic SIEM
Elastic Security
Kibana
Elasticsearch
Logstash
Beats
Fleet
SOAR
Microsoft Sentinel
QRadar
Splunk
Azure
AWS
Python
PowerShell
Bash
MITRE ATT&CK

Job description

Job description

We look forward to connecting with talented professionals in the Cybersecurity domain.

Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)
We are looking for experienced Cybersecurity to join our team.
Job Description - SOC L3 Engineer (Elastic SIEM & SOAR)

Location: Bengaluru
Role: SOC L3 / Senior Security Operations Engineer

Role Summary

Seeking an experienced SOC L3 professional with strong expertise in Elastic Security (SIEM) and SOAR platforms. The candidate should possess hands‑on experience in SIEM implementation, administration, content engineering, threat hunting, incident response, and SOC optimization across multiple SIEM technologies such as Microsoft Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic, or similar platforms.

Key Responsibilities
  • Lead L3 investigations for complex security incidents and advanced threats.
  • Design, implement, and optimize Elastic SIEM and Elastic Security deployments.
  • Develop and maintain SOAR playbooks, automation workflows, and integrations.
  • Build and tune detection rules, correlation logic, dashboards, alerts, and threat hunting content.
  • Support end-to-end SIEM implementation including onboarding log sources, parsing, normalization, and data pipelines.
  • Perform threat hunting, malware analysis, and root cause investigations.
  • Provide technical guidance to L1/L2 analysts and lead incident response activities.
  • Integrate threat intelligence feeds and improve detection maturity.
  • Conduct use case development, validation, and security monitoring enhancements.
  • Participate in SOC transformation, SIEM migrations, and platform evaluations.
Required Technical Skills
  • Strong hands‑on experience with Elastic SIEM / Elastic Security.
  • Experience with Elastic Defend, Kibana, Elasticsearch, Logstash, Beats, Fleet, and detection engineering.
  • Hands‑on experience in SOAR implementation and automation orchestration.
  • Experience implementing or managing other SIEM platforms such as Microsoft Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic, Stellar Cyber, or equivalent.
  • Strong understanding of Windows, Linux, Active Directory, Azure, AWS, networking, and cloud security.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, IOC analysis, and threat intelligence.
  • Experience with scripting (Python, PowerShell, Bash) for automation.
  • Understanding of EDR/XDR, NDR, Email Security, IAM, and Security Controls integration.
Preferred Certifications

Elastic Certified Engineer, Microsoft SC-200, AZ-500, Splunk, QRadar, GCIH, GCIA, CEH, CISSP, or equivalent certifications.

Soft Skills

Strong analytical and troubleshooting skills, stakeholder communication, client-facing experience, documentation skills, mentoring capability, and ability to lead critical security incidents.

Deal Breaker Skill

Elastic Search

Mandatory Skills

Elastic Search

| Elastic SIEM

| ELK

| Soar Automation

| Elastic Security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L3 Engineer
L3 Engineer

Happiest Minds Technologies • Bengaluru

On-site
INR 1,200,000 - 2,500,000
SOC L3 Engineer (Elastic SIEM & SOAR)
SOC L3 Engineer (Elastic SIEM & SOAR)

Happiest Minds Technologies • Dadri, Pune District, Bengaluru

Hybrid
INR 1,400,000 - 2,100,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner

Innova ESI • Mumbai

On-site
INR 800,000 - 1,200,000
Sr IT Security Analyst SIEM SOAR
Sr IT Security Analyst SIEM SOAR

Technogen • Hyderabad

Hybrid
INR 4,500,000 - 7,500,000
L3 SOC, SIEM Tools Expert _Gurgaon_Onsite
L3 SOC, SIEM Tools Expert _Gurgaon_Onsite

NTT DATA, Inc. • Gurugram District

On-site
INR 3,000,000 - 5,400,000
Senior SOC (Security Operations Center) Analyst
Senior SOC (Security Operations Center) Analyst

Orcapod Consulting Services • Mumbai

Hybrid
INR 1,200,000 - 1,800,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Senior Consultant-SOC L3-SIEM Engineering | Experience: 5+ Years
Senior Consultant-SOC L3-SIEM Engineering | Experience: 5+ Years

Aujas Networks Pvt. Ltd. • Bengaluru, Gurugram District, Mumbai

On-site
INR 1,200,000 - 1,500,000
Cyber Security Specialist
Cyber Security Specialist

Terralogic • Bengaluru

On-site
INR 2,500,000 - 4,200,000