Lead Cybersecurity Engineer

Providence Health & Services

Hyderabad

On-site

INR 3,500,000 - 4,500,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Providence Health & Services in Hyderabad is seeking a SIEM Lead Engineer to drive design, development, and optimization of SIEM alerting and monitoring using Splunk. You will lead detection engineering, tune correlations, and mentor a team of SIEM professionals, collaborating with SOC, Threat Detection, and Security Engineering.

Strong experience in Splunk and MITRE ATT&CK required. This role focuses on reducing false positives, enriching alerts with contextual data, and ensuring CIM compliance

Qualifications

  • 6-10 years of experience in SIEM or security engineering roles.
  • Strong hands-on expertise with Splunk Enterprise / Splunk ES.
  • Proven experience in SIEM alert development, tuning, and enrichment.
  • Strong understanding of security telemetry across endpoint, network, cloud, and IAM.
  • Proficiency in SPL (Search Processing Language).
  • Experience with MITRE ATT&CK and SOC workflows.
  • Experience integrating SIEM with IAM, CMDB, vulnerability, and threat intel platforms.

Responsibilities

  • Lead engineering and optimization of Splunk-based SIEM alerting and monitoring.
  • Design, develop, and tune correlation rules and detections to reduce false positives.
  • Own alert lifecycle management including creation, tuning, validation, and retirement.
  • Design and implement alert enrichment using IAM, CMDB, vulnerability, and threat intelligence sources.
  • Ensure alerts are enriched with user, asset, privilege, and business context.
  • Engineer and maintain Splunk data ingestion, normalization, and CIM compliance.
  • Support onboarding of log sources across endpoint, network, cloud, and identity platforms.
  • Develop detection use cases mapped to MITRE ATT&CK.
  • Act as L3 escalation for complex SIEM and detection issues.
  • Maintain SOPs, runbooks, and SIEM documentation.
  • Mentor SIEM engineers and provide technical guidance.

Skills

SIEM design & implementation
Splunk Enterprise / Splunk ES
Alert tuning & enrichment
SPL
MITRE ATT&CK mapping
SOC workflows
Threat detection engineering
L3 escalation support

Tools

Splunk Enterprise

Job description

Job Description:

Job Description - SIEM Lead Engineer
Role Overview

The SIEM Lead Engineer is responsible for leading the design, development, and optimization of SIEM alerting, enrichment, and monitoring capabilities using Splunk. This role focuses on improving alert fidelity, contextual enrichment, detection engineering, and overall SOC effectiveness. The role acts as a technical lead and escalation point, working closely with SOC Analysts, Threat Detection, Security Engineering, and platform teams.

Key Responsibilities
  • Lead engineering and optimization of Splunk-based SIEM alerting and monitoring.
  • Design, develop, and tune correlation rules and detections to reduce false positives.
  • Own alert lifecycle management including creation, tuning, validation, and retirement.
  • Design and implement alert enrichment using IAM, CMDB, vulnerability, and threat intelligence sources.
  • Ensure alerts are enriched with user, asset, privilege, and business context.
  • Engineer and maintain Splunk data ingestion, normalization, and CIM compliance.
  • Support onboarding of log sources across endpoint, network, cloud, and identity platforms.
  • Develop detection use cases mapped to MITRE ATT&CK.
  • Act as L3 escalation for complex SIEM and detection issues.
  • Maintain SOPs, runbooks, and SIEM documentation.
  • Mentor SIEM engineers and provide technical guidance.
Required Skills & Experience
  • 6-10 years of experience in SIEM or security engineering roles.
  • Strong hands-on expertise with Splunk Enterprise / Splunk ES.
  • Proven experience in SIEM alert development, tuning, and enrichment.
  • Strong understanding of security telemetry across endpoint, network, cloud, and IAM.
  • Proficiency in SPL (Search Processing Language).
  • Experience with MITRE ATT&CK and SOC workflows.
  • Experience integrating SIEM with IAM, CMDB, vulnerability, and threat intel platforms.
Preferred Qualifications
  • Experience in regulated environments such as healthcare or financial services.
  • Exposure to SOAR platforms and automated response workflows.
  • Scripting experience using Python or PowerShell.
  • Relevant security or Splunk certifications.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SIEM Engineer - Contract
SIEM Engineer - Contract

Gravity Infosolutions, Inc. • India

On-site
INR 1,200,000 - 1,800,000
Soc Analyst
Soc Analyst

PwC India • Bengaluru

On-site
INR 1,400,000 - 2,200,000
Sr. Consultant
Sr. Consultant

Tribastion Technologies Pvt. Ltd. • India

On-site
INR 1,000,000 - 1,500,000
Siem Engineer
Siem Engineer

Tata Consultancy Services • Ernakulam

On-site
INR 1,500,000 - 3,000,000
SIEM Integrator
SIEM Integrator

SolarEdge Technologies • Bengaluru

On-site
INR 900,000 - 1,500,000
Splunk Engineer
Splunk Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,800,000
Splunk certification support
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Neurealm • Chennai District

On-site
INR 2,800,000 - 6,000,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Security Analyst L3– SIEM (Splunk Administrator)
Security Analyst L3– SIEM (Splunk Administrator)

HR Path • Bengaluru

On-site
INR 800,000 - 1,200,000
Splunk Engineer
Splunk Engineer

EMBARKGCC SERVICES PRIVATE LIMITED • Bengaluru Urban

On-site
INR 900,000 - 1,400,000