SIEM Content Developer

Persistent Systems

Pune District

Hybrid

INR 3,000,000 - 6,000,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Persistent Systems is seeking an experienced SIEM Content Developer (Splunk) to design, develop, tune, and maintain detection content for a Global SOC. The role focuses on reducing false positives, building risk-based alerts, and aligning detections with MITRE ATT&CK across endpoints, networks, cloud, and identity logs.

You will collaborate closely with SOC analysts, threat hunters, incident response teams, and security architects to deliver high-fidelity alerts and comprehensive runbooks for

Qualifications

  • Hands-on Splunk design, development, and tuning experience.
  • Experience building detections, dashboards, and RBAs aligned to MITRE ATT&CK.
  • Solid SOC operations and incident response familiarity.
  • Knowledge of data onboarding, CIM normalization, and TA configuration.

Responsibilities

  • Design, develop, and maintain Splunk correlation searches and alerts.
  • Translate threats into Splunk detections and runbooks.
  • Develop detections across EDR, network, cloud, identity, and apps/logs.
  • Tune alerts to reduce false positives and optimize performance.
  • Collaborate with SOC L1-L3 and support IR/ threat hunting activities.
  • Map detections to MITRE techniques and define responses.

Skills

Splunk Enterprise
Splunk ES
SPL
Correlation searches
Notables
Dashboards
RBA
SOC operations
Incident response
Threat hunting
Purple Team
Content migration
CIM normalization
TA configuration
MITRE ATT&CK
Splunk SOAR
XSOAR Palo Alto
Endpoint/Cloud logs

Education

Bachelor's degree in a relevant discipline

Tools

Splunk SOAR
Palo Alto XSOAR
QRadar
ArcSight
CrowdStrike Defender
Carbon Black
Active Directory / Azure AD
Okta
AWS/Azure/GCP logs
Zscaler

Job description

The SIEM Content Developer Splunk is a critical role within our Global Security Operations Center (SOC). This position is responsible for designing, developing, tuning, and maintaining Splunk detection content to enhance threat detection, incident response, and security monitoring across enterprise environments. The ideal candidate will collaborate closely with SOC analysts, threat hunters, incident response teams, and security architects to ensure the delivery of high-fidelity alerts with minimal false positives, all while aligning with the MITRE ATT&CK framework.

  • Location: Pune
  • Experience: Between 8 to 12 Years
  • Job Type: Full Time Employment
What You’ll Do:
  • Design, develop, and maintain Splunk correlation searches, alerts, and dashboards.
  • Build use-case driven detections aligned to MITRE ATT&CK techniques.
  • Create risk-based alerting (RBA) and notable events.
  • Maintain version-controlled SIEM content lifecycle (development, testing, production). Detection Use Case Development
  • Translate threat scenarios, attack paths, and TTPs into Splunk detections.
  • Develop detections for various environments including Endpoint (EDR, Windows, Linux, macOS), Network (Firewall, IDS/IPS, Proxy, VPN), Cloud (AWS, Azure, GCP security logs), Identity (AD, Azure AD, Okta), and Application & Database logs.
  • Map detections to MITRE techniques, severity, and response actions.
  • Tuning & Optimization
  • Perform alert tuning and false-positive reduction. Optimize SPL queries for performance and scalability.
  • Improve signal-to-noise ratio through context enrichment and suppression logic. SOC & IR Enablement Work with SOC L1/L2/L3 teams to refine alert logic.
  • Create runbooks and investigation guidance for each detection.
  • Support incident response and threat hunting activities.
  • Assist with Purple Team exercises and detection gap analysis. Documentation & Governance
  • Maintain use case documentation, data source dependencies, and logic flows.
  • Support audits and compliance reporting where SIEM evidence is required.
Expertise You'll Bring:
  • Strong hands-on experience with Splunk Enterprise / Splunk ES.
  • Advanced proficiency in SPL (Search Processing Language).
  • Experience building correlation searches, notables, dashboards, and RBA.
  • Solid understanding of SOC operations and incident response workflows.
  • Strong knowledge of the MITRE ATT&CK framework.
  • Log Source Experience: Endpoint (CrowdStrike, Defender, Carbon Black), Network (Palo Alto, Cisco, Fortinet, Zscaler), Cloud (AWS CloudTrail, Azure Activity Logs, GCP logs), Identity (Active Directory, Azure AD, Okta), Email & SaaS (Proofpoint, O365, Google Workspace).
  • Experience with SOAR integration (Splunk SOAR, Palo Alto XSOAR).
  • Threat hunting and Purple Team collaboration.
  • Experience with content migration from other SIEMs (QRadar, Sentinel, ArcSight).
  • Knowledge of data onboarding, CIM normalization, and TA configuration.
  • Certifications (Preferred) Splunk Enterprise Security Certified Admin.
  • Splunk Core Power User / Admin.
  • GIAC GCED / GCIA / GCIH.
  • Educational background: Bachelor's degree in a relevant discipline or equivalent practical experience.
  • Competitive salary and benefits package
  • Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
  • Opportunity to work with cutting-edge technologies
  • Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
  • Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment:
  • We support hybrid work and flexible hours to fit diverse lifestyles.
  • Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
  • If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment

Let’s unleash your full potential at Persistent - persistent.com/careers

“Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.”

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Content Developer
SIEM Content Developer

Persistent • Pune District

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work
Education benefits
Health check-ups
+1
Programmer (Dev) – SOC Analyst
Programmer (Dev) – SOC Analyst

Persistent Systems • Pune District

Hybrid
INR 700,000 - 1,000,000
Group term life insurance
Mediclaim hospitalization
Flexible work hours
+3
Splunk Engineer
Splunk Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,800,000
Splunk certification support
Programmer (Dev)-SOC Analyst
Programmer (Dev)-SOC Analyst

Persistent • Pune District

On-site
INR 700,000 - 1,000,000
Competitive salary
Talent development with certifications
Work with cutting-edge technologies
+1
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Providence India • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Soc Analyst
Soc Analyst

PwC India • Bengaluru

On-site
INR 1,400,000 - 2,200,000
SME - Security Analysis, SIEM
SME - Security Analysis, SIEM

HCL Technologies Limited • Pune District

On-site
INR 1,800,000 - 3,200,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Providence Global Center • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Competitive Pay
Supportive Reporting Relation
Security Technician
Security Technician

Fujitsu • Pune District

On-site
INR 1,500,000 - 2,800,000
Relocation assistance
Splunk Engineer / Senior Splunk Engineer
Splunk Engineer / Senior Splunk Engineer

Giesecke & Devrient GB Ltd. • Pune District

On-site
INR 1,200,000 - 2,000,000