SIEM Content Development Specialist - Cyber Defence - VOIS

Vodafone Group Plc

Pune District

On-site

INR 1,200,000 - 1,800,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Vodafone Group Plc's VOIS unit is seeking a SIEM Content Development Specialist to strengthen Cyber Defence within the CSOC. You will design, develop, and optimise detection content across Elastic/ELK and other platforms, collaborating with stakeholders to translate requirements into actionable rules.

You should bring 10+ years in SOC operations or security engineering, strong scripting (Python/PowerShell), cloud telemetry (AWS/Azure/GCP), and a solid understanding of MITRE ATT&CK.

Qualifications

  • 10+ years in SOC operations or SIEM content development, threat hunting, or security engineering.
  • Experience with SIEM technologies including Elastic/ELK, Splunk, Sentinel, ArcSight or Chronicle.
  • Proficiency in programming/scripting (Python, SQL, JavaScript, PowerShell, KQL).
  • Strong cloud telemetry knowledge across AWS, Azure, GCP.
  • Experience aligning detections with MITRE ATT&CK and kill chain models.
  • Regex and data analysis expertise.
  • Solid networking knowledge (TCP/IP, CIDR, subnets).
  • Certifications such as CISSP or SANS (GCIH/GCIA) are advantageous.

Responsibilities

  • Design, develop, and optimise SIEM detection content across platforms.
  • Lead SIEM content engineering initiatives using SDLC and Agile practices.
  • Refine detection rules to improve SOC efficiency and coverage.
  • Develop threat response workflows and playbooks.
  • Conduct threat analysis to design behavioural and indicator-based detections.
  • Collaborate with log source owners to translate requirements into SIEM content.
  • Deliver security reports and advisories to stakeholders.
  • Perform post-incident analysis and drive improvements; support EDR/XDR tuning.
  • Create and maintain technical docs, workflows, and playbooks.

Skills

SIEM content development
Threat hunting
Security engineering
Regex
Networking concepts

Tools

Elastic/ELK
Splunk
Sentinel
ArcSight
Chronicle
Python
SQL
JavaScript
PowerShell
KQL

Job description

Who we areVOIS (Vodafone Intelligent Solutions) is a strategic arm of Vodafone Group Plc, creating value for customers by delivering intelligent solutions through Talent, Technology & Transformation.As the largest shared services organisation in the global telco industry with 30,000 FTE, our portfolio of next-generation solutions and services are designed in partnership with customers across Vodafone Group, local markets, and partner markets to simplify and drive growth. With our strategic partner Accenture, we work alongside our Vodafone customers, other Telco and tech companies to drive transformation, meet the challenges of our industry and ensure we stay relevant and resilient. This partnership is a unique, industry-first model which brings together the best of in-house and 3rd party capability.We work with customers across 28 countries from 10 VOIS locations: Albania, Egypt, Hungary, India, Romania, Spain, Turkey, UK, Germany, Ireland, and with a network of teams in Czech Republic, Italy, Greece, and Portugal.#VOIS #BeUnrivalled #CreateTheFutureAbout this RoleWe are seeking a SIEM Content Development Specialist to strengthen Cyber Defence detection capabilities within the Cyber Security Operations Centre (CSOC). The role focuses on developing and refining SIEM detection content, leveraging knowledge of threat landscapes, MITRE ATT&CK techniques, and organisational risks. The individual will work closely with stakeholders to create actionable detection logic, enhance threat visibility, and improve response efficiency across Vodafone’s cyber defence ecosystem.What you’ll doDesign, develop, and optimise SIEM detection content across existing and new platformsLead and contribute to SIEM content engineering initiatives, applying SDLC and Agile methodologiesContinuously refine detection rules and logic to improve SOC efficiency and effectivenessDevelop and integrate threat response workflows and playbooksConduct threat analysis to design behavioural and indicator-based detection use casesCollaborate with log source owners to translate business and technical requirements into actionable SIEM contentDeliver cyber security reports and advisories to key stakeholdersPerform post-incident analysis and drive improvements through actionable insightsSupport EDR/XDR detection engineering and tuning activitiesCreate and maintain technical documentation, workflows, and operational playbooksWho you areExperienced professional with 10+ years in SOC operations, SIEM content development, threat hunting, or security engineeringSkilled in SIEM technologies, particularly Elastic/ELK, with knowledge of platforms such as Splunk, Sentinel, ArcSight, or ChronicleProficient in programming and scripting (e.g., Python, SQL, JavaScript, PowerShell, KQL, ES|QL)Strong understanding of cloud environments (AWS, Azure, GCP) and associated telemetryExperienced in developing detection use cases and threat scenarios aligned with MITRE ATT&CK and cyber kill chain frameworksCompetent in Regex and data analysis techniquesKnowledgeable in networking concepts (TCP/IP, CIDR, subnets) and security tools (IDS/IPS, firewalls, AV systems)Strong analytical, problem-solving, and communication skillsAble to work independently, prioritise tasks, and collaborate effectively across teamsCertifications such as CISSP or SANS (e.g., GCIH, GCIA) are advantageousNot a perfect fit?Concerned you may not meet every requirement? Vodafone is committed to creating an inclusive workplace where everyone can thrive. If you are excited about this role but your experience does not align exactly with every aspect of the job description, you are encouraged to apply. You may be the right candidate for this or another opportunity, and the recruitment team will support you in exploring where your skills fit best.What's in it for youOpportunity to work at the core of global cyber defence operationsExposure to advanced SIEM, EDR, and XDR technologies and large-scale security environmentsCollaboration with global cyber security experts and stakeholdersContinuous learning through evolving threat landscapes and modern security frameworksOpportunity to contribute to meaningful risk reduction initiatives across VodafoneWhat skills you will learnAdvanced SIEM content engineering and detection optimisation techniquesPractical implementation of MITRE ATT&CK and threat intelligence frameworksCyber threat analysis, behavioural detection modelling, and incident response improvementsCloud security monitoring and telemetry integrationCross-functional collaboration and stakeholder communication within global security environmentsVOIS Equal Opportunity Employer CommitmentVodafone recognises and celebrates the value of diversity in building a workforce that reflects the customers and communities it serves. No form of discrimination is tolerated. This includes, but is not limited to, discrimination based on race, colour, age, veteran status, gender identity, gender expression, sexual orientation, pregnancy, maternity or parental status, ethnicity, disability, religion or belief, political affiliation, trade union membership, nationality, citizenship, indigenous status, medical condition, HIV status, neurodiversity, social origin, cultural background, marital or civil partnership status, or socio-economic background.Join UsAt Vodafone, we’re working hard to build a better future. A more connected, inclusive and sustainable world. As a dynamic global community, it's our human spirit, together with technology, that empowers us to achieve this.We challenge and innovate in order to connect people, businesses, and communities across the world. Delighting our customers and earning their loyalty drive us, and we experiment, learn fast and get it done, together.With us, you can truly be yourself and belong, share inspiration, embrace new opportunities, thrive, and make a real difference.AlertApply for Vodafone jobs only through the official Vodafone Careers website to avoid job scams and fraud.#JDEnhancedByTARAFollow us on social mediaLinkedIn: https://www.linkedin.com/company/vois/Facebook: https://www.facebook.com/voisglobalInstagram: https://www.instagram.com/voisglobal/
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SIEM Content Development Specialist - Cyber Defence - VOIS
SIEM Content Development Specialist - Cyber Defence - VOIS

VOIS • Maharashtra

On-site
INR 900,000 - 1,500,000
SOC Lead - Cyber Security Operations - VOIS
SOC Lead - Cyber Security Operations - VOIS

VOIS • Bengaluru

On-site
INR 3,000,000 - 7,000,000
Cybersecurity -Risk Management assessment
Cybersecurity -Risk Management assessment

VOIS • Maharashtra

On-site
INR 1,800,000 - 2,600,000
SIEM Engineer - VOIS
SIEM Engineer - VOIS

Vodafone Group Plc • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Full Stack Developer - VOIS
Full Stack Developer - VOIS

Vodafone Group Plc • Pune District

On-site
INR 2,000,000 - 3,200,000
Customer Success Manager-Deputy Manager-Bangalore
Customer Success Manager-Deputy Manager-Bangalore

Vodafone Group Plc • Pune District

On-site
INR 250,000 - 450,000
Cybersecurity -Risk Management assessment
Cybersecurity -Risk Management assessment

Vodafone Group Plc • Pune District

On-site
INR 3,500,000 - 5,200,000
AWS Network & Security Specialist - VOIS
AWS Network & Security Specialist - VOIS

VOIS • Maharashtra

On-site
INR 1,500,000 - 2,300,000
SENIOR DEVOPS ENGINEER (CLOUD & PLATFORM RELIABILITY) - VOIS Pune, Maharashtra, India Digital E[...]
SENIOR DEVOPS ENGINEER (CLOUD & PLATFORM RELIABILITY) - VOIS Pune, Maharashtra, India Digital E[...]

Vodafone Group Plc • Pune District

On-site
INR 1,200,000 - 1,800,000
Continuous learning opportunities
Exposure to modern DevOps tools
Collaborative team environment
Secure By Design - VOIS
Secure By Design - VOIS

VOIS • Maharashtra

On-site
INR 1,200,000 - 1,900,000