SIEM Engineer L3

Capgemini

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Capgemini is seeking an experienced SIEM Engineer L3 to ensure accurate, normalized, enriched, and queryable security telemetry for monitoring, detection, investigation, and threat hunting. You will design data onboarding solutions, create integrations and parsers, and validate data quality across telemetry pipelines.

You will collaborate with multiple teams to build scalable ingestion pipelines, maintain documentation, and support SOC platforms including SIEM, Data Lake, and SOAR.

Qualifications

  • Hands-on experience with Microsoft Sentinel and security telemetry onboarding.
  • Experience onboarding telemetry and building connectors for large-scale log ingestion.
  • Ability to validate data quality and maintain thorough documentation.

Responsibilities

  • Design, implement, and optimize security telemetry ingestion pipelines into SIEM and SOC platforms.
  • Build connectors, API integrations, and ingestion mechanisms for diverse data sources.
  • Develop parsing, normalization, and transformation logic using KQL, Regex, Grok, and ASIM/OCSF.
  • Collaborate with engineering teams to ensure telemetry supports detection and cost efficiency.
  • Monitor and improve ingestion pipelines, data quality, and documentation.

Skills

SIEM ingestion
Telemetry pipelines
Regex parsing
KQL queries
Azure Functions
Azure Data Explorer
Event Hub
Syslog collection
Data quality
Threat hunting
Monitoring & reporting

Tools

Databricks
Cribl Stream
Logstash
Syslog-ng
Azure Monitor Agent
Azure Data Lake

Job description

As a SIEM Engineer L3 at Capgemini, you will be responsible for ensuring that the SOC has accurate, complete, normalized, enriched, and queryable security telemetry required for monitoring, detection, investigation, threat hunting, automation, and reporting. You will design and implement data onboarding solutions, develop integrations and parsers, validate data quality, and collaborate with multiple teams to build scalable and reliable telemetry pipelines.

  • Design, implement, and optimize security telemetry ingestion pipelines into SIEM, Data Lake, SOAR, and other SOC platforms using native and custom integrations.
  • Build, configure, and maintain connectors, API integrations, Azure Functions, Event Hub pipelines, syslog collectors, and custom ingestion mechanisms for diverse security data sources.
  • Develop and manage parsing, normalization, schema mapping, enrichment, deduplication, and transformation logic using KQL, Regex, Grok, ASIM, OCSF, and related frameworks.
  • Collaborate with Detection Engineering, Platform Engineering, and technology owners to ensure telemetry supports detection use cases, operational stability, and cost-effective scalability.
  • Monitor, troubleshoot, and improve ingestion pipelines, data quality, connector health, telemetry coverage, and onboarding processes while maintaining comprehensive technical documentation.
Your Profile
  • Hands-on experience with Microsoft Sentinel, security telemetry onboarding, custom connector development, API integrations, and large-scale log ingestion platforms such as Azure Data Explorer, Azure Data Lake, Databricks, Cribl Stream, Logstash, or syslog-ng.
  • Strong understanding of log collection methodologies including syslog, APIs, agent-based collection, cloud-native integrations, event streaming, custom logs, Azure Monitor Agent, Event Hub, and Azure Functions.
  • Expertise in data parsing, normalization, schema alignment, enrichment, and transformation using KQL, Regex, Grok, ASIM, OCSF, and security data models.
  • Good knowledge of security telemetry across endpoint, identity, email, network, firewall, DNS, cloud, SaaS, OT/ICS, vulnerability management, and asset inventory environments, along with MITRE ATT&CK data source mapping.
  • Experience in troubleshooting telemetry pipelines, validating data quality, managing ingestion monitoring, ensuring analyst usability, supporting detection requirements, and maintaining detailed documentation in regulated enterprise environments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Detection Engineer L3
Detection Engineer L3

Capgemini • Bengaluru

On-site
INR 1,200,000 - 1,800,000
L3 Engineer
L3 Engineer

Happiest Minds Technologies • Bengaluru

On-site
INR 1,200,000 - 2,500,000
SOC L3 Engineer (Elastic SIEM & SOAR)
SOC L3 Engineer (Elastic SIEM & SOAR)

Happiest Minds Technologies • Dadri, Pune District, Bengaluru

Hybrid
INR 1,400,000 - 2,100,000
SOC L2 Analyst
SOC L2 Analyst

Capgemini • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)
Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)

IT MNC • Karnataka

On-site
INR 1,500,000 - 2,000,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Providence India • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Sr IT Security Analyst SIEM SOAR
Sr IT Security Analyst SIEM SOAR

Technogen • Hyderabad

Hybrid
INR 4,500,000 - 7,500,000
Lead Assistant Manager-SIEM
Lead Assistant Manager-SIEM

EXL • Dadri

Hybrid
INR 1,500,000 - 2,100,000
L2 SOC Security Engineer (SIEM / SOAR / UEBA) 3 to 4 Years
L2 SOC Security Engineer (SIEM / SOAR / UEBA) 3 to 4 Years

Black Box Corporation • Gurgaon

On-site
INR 800,000 - 1,200,000