SIEM Content Developer

Persistent

Pune District

Hybrid

INR 1,200,000 - 1,800,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work
Education benefits
Health check-ups
Insurance coverage

Job summary

Persistent is seeking an experienced SIEM Content Developer Splunk in Pune. The role focuses on designing, developing, tuning, and maintaining Splunk detection content to enhance threat detection and incident response across enterprise environments.

You will collaborate with SOC analysts and threat hunters to deliver high-fidelity alerts with minimal false positives, aligned with MITRE ATT&CK techniques and across endpoint, network, cloud, identity, and application logs.

Qualifications

  • 8–12 years of SIEM/security operations experience.
  • Strong SPL proficiency and content development skills.
  • Experience mapping detections to MITRE ATT&CK techniques.

Responsibilities

  • Design, develop, tune, and maintain Splunk detection content.
  • Build correlation searches, alerts, and dashboards.
  • Create risk-based alerting and notable events.
  • Map detections to MITRE techniques, severity, and response actions.
  • Tune alerts to reduce false positives and optimize performance.
  • Develop runbooks and investigation guidance for detections.

Skills

Splunk ES
SPL
SIEM content development
MITRE ATT&CK mapping
SOC operations

Education

Bachelor's degree

Tools

Splunk Enterprise Security
Splunk SOAR
QRadar
ArcSight

Job description

About Position:

The SIEM Content Developer Splunk is a critical role within our Global Security Operations Center (SOC). This position is responsible for designing, developing, tuning, and maintaining Splunk detection content to enhance threat detection, incident response, and security monitoring across enterprise environments. The ideal candidate will collaborate closely with SOC analysts, threat hunters, incident response teams, and security architects to ensure the delivery of high-fidelity alerts with minimal false positives, all while aligning with the MITRE ATT&CK framework.

  • Role: SIEM Content Developer Splunk
  • Location: Pune
  • Experience: Between 8 to 12 Years
  • Job Type: Full Time Employment
What You'll Do:
  • SIEM Content Engineering
  • Design, develop, and maintain Splunk correlation searches, alerts, and dashboards.
  • Build use-case driven detections aligned to MITRE ATT&CK techniques.
  • Develop SPL queries for complex detection logic across diverse log sources.
  • Create risk-based alerting (RBA) and notable events.
  • Maintain version-controlled SIEM content lifecycle (development, testing, production). Detection Use Case Development
  • Translate threat scenarios, attack paths, and TTPs into Splunk detections.
  • Develop detections for various environments including Endpoint (EDR, Windows, Linux, macOS), Network (Firewall, IDS/IPS, Proxy, VPN), Cloud (AWS, Azure, GCP security logs), Identity (AD, Azure AD, Okta), and Application & Database logs.
  • Map detections to MITRE techniques, severity, and response actions.
  • Tuning & Optimization
  • Perform alert tuning and false-positive reduction. Optimize SPL queries for performance and scalability.
  • Improve signal-to-noise ratio through context enrichment and suppression logic. SOC & IR Enablement Work with SOC L1/L2/L3 teams to refine alert logic.
  • Create runbooks and investigation guidance for each detection.
  • Support incident response and threat hunting activities.
  • Assist with Purple Team exercises and detection gap analysis. Documentation & Governance
  • Maintain use case documentation, data source dependencies, and logic flows.
  • Support audits and compliance reporting where SIEM evidence is required.
  • Track coverage metrics (ATT&CK coverage, detection maturity).
Expertise You'll Bring:
  • Strong hands-on experience with Splunk Enterprise / Splunk ES.
  • Advanced proficiency in SPL (Search Processing Language).
  • Experience building correlation searches, notables, dashboards, and RBA.
  • Solid understanding of SOC operations and incident response workflows.
  • Strong knowledge of the MITRE ATT&CK framework.
  • Log Source Experience: Endpoint (CrowdStrike, Defender, Carbon Black), Network (Palo Alto, Cisco, Fortinet, Zscaler), Cloud (AWS CloudTrail, Azure Activity Logs, GCP logs), Identity (Active Directory, Azure AD, Okta), Email & SaaS (Proofpoint, O365, Google Workspace).
  • Experience with SOAR integration (Splunk SOAR, Palo Alto XSOAR).
  • Threat hunting and Purple Team collaboration.
  • Experience with content migration from other SIEMs (QRadar, Sentinel, ArcSight).
  • Knowledge of data onboarding, CIM normalization, and TA configuration.
  • Certifications (Preferred) Splunk Enterprise Security Certified Admin.
  • Splunk Core Power User / Admin.
  • GIAC GCED / GCIA / GCIH.
  • MITRE ATT&CK Defender (MAD).
  • Educational background: Bachelor's degree in a relevant discipline or equivalent practical experience.
Benefits:
  • Competitive salary and benefits package
  • Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
  • Opportunity to work with cutting-edge technologies
  • Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
  • Annual health check-ups
  • Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment:

Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.

  • We support hybrid work and flexible hours to fit diverse lifestyles.
  • Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
  • If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment

"Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind."

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Content Developer
SIEM Content Developer

Persistent Systems • Pune District

Hybrid
INR 3,000,000 - 6,000,000
Programmer (Dev)-SOC Analyst
Programmer (Dev)-SOC Analyst

Persistent • Pune District

On-site
INR 700,000 - 1,000,000
Competitive salary
Talent development with certifications
Work with cutting-edge technologies
+1
Programmer (Dev) – SOC Analyst
Programmer (Dev) – SOC Analyst

Persistent Systems • Pune District

Hybrid
INR 700,000 - 1,000,000
Group term life insurance
Mediclaim hospitalization
Flexible work hours
+3
Splunk Engineer
Splunk Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,800,000
Splunk certification support
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Providence India • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Splunk Engineer / Senior Splunk Engineer
Splunk Engineer / Senior Splunk Engineer

Giesecke & Devrient GB Ltd. • Pune District

On-site
INR 1,200,000 - 2,000,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Providence Global Center • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Competitive Pay
Supportive Reporting Relation
SOC Manager
SOC Manager

Persistent • Pune District

Hybrid
INR 4,000,000 - 7,000,000
Competitive salary and benefits
Quarterly growth opportunities
Company-sponsored higher education &
+3
SME - Security Analysis, SIEM
SME - Security Analysis, SIEM

HCL Technologies Limited • Pune District

On-site
INR 1,800,000 - 3,200,000
SIEM Integrator
SIEM Integrator

SolarEdge Technologies Inc. • Bengaluru

On-site
INR 1,500,000 - 2,500,000
SOAR experience
Security certifications
Regulated logging experience