SIEM SOAR Engineer

Tata Consultancy Services

Ahmedabad District, Chennai District

On-site

INR 1,500,000 - 2,100,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Tata Consultancy Services seeks a SecOps SIEM SOAR Engineer for Google Cloud Professional Services. You will extend UDMs, create custom parsers, and integrate SecOps SIEM with SOAR, EDR, NDR, threat intel, and ticketing systems.

Responsibilities include scripting, developing SOAR playbooks, incident response, and scaling deployments in high-volume security environments while maintaining cloud security program maturity.

Qualifications

  • Hands-on experience configuring and extending SIEM/SOAR platforms.
  • Experience with log ingestion, parsing, normalization and dashboarding.
  • Ability to design and implement SOC playbooks and incident response procedures.

Responsibilities

  • Extend UDMs and create custom parsers for log sources.
  • Integrate Google SecOps SIEM with SOAR, EDR, NDR, threat intel and ticketing systems.
  • Write custom actions, scripts and integrations to extend SIEM/SOAR functionality.
  • Monitor performance and scale SIEM/SOAR in high-volume environments.
  • Create SIEM assets like detection rules, dashboards, parsers and reports.
  • Migrate assets to SecOps and assist in phase-out/phase-in.
  • Test and deploy assets such as rules, playbooks and alerts.
  • Design solutions to reduce alert fatigue in SIEM correlation.
  • Develop custom dashboards to meet customer requirements.
  • Guide on building cloud security programs and implementations.

Skills

SIEM
SOAR
Cloud security
Incident response

Tools

YARA-L
Google SecOps

Job description

SecOps SIEM SOAR Engineer, Google Cloud Professional Services
  • Extension of pre-built UDMs in Google SecOps and creation of custom parsers where required for log sources.
  • Integration of Google SecOps SIEM with other security capabilities and tools such as SOAR, EDR, NDR, threat intelligence platform, and ticketing systems.
  • Write custom actions, scripts and/or integrations to extend SIEM platform functionality.
  • Monitor performance and perform timely actions to scale SIEM deployment, especially in a very high-volume security environment.
  • Creation of SIEM assets such as: detection rules using YARA-L, dashboards, parsers etc.
  • Migration of existing assets from existing customers SIEM/SOAR to SecOps and assisting in implementing the SIEM/SOAR phase-out, phase-in approach.
  • Testing and deployment of newly created and migrated assets such as rules, playbooks, alerts, dashbords etc
  • Design and implement solutions to handle alert fatigue encountered in SIEM correlation.
  • Creation of custom SIEM dashboards to meet customer requirements.
  • Guide on building or maturing cloud security programs and the implementation of tools and approaches used for improving cloud security.
  • Debug and solve customer issues in ingestion, parsing, normalization of data etc
  • Develop SOAR playbooks to provide case handling and Incident response as per triage needs
  • Lead the design and implementation of Google SecOps SOAR playbooks for security use cases, such as phishing incident response, vulnerability triage, or threat hunting on Google SecOps based on specific threat models.
  • Integration of Google SecOps SOAR with other security capabilities and tools such as SIEM, EDR, NDR threat intelligence platform, and ticketing systems.
  • Design testing and conduct validation of SOAR playbooks before deployment to live environment.
  • Write custom actions, scripts and/or integrations to extend SOAR platform functionality.
  • Monitor performance and perform timely actions to scale SOAR deployment, especially in a high-volume security environment.
  • Migration of existing assets from existing customers SIEM/SOAR to SecOps and assisting in implementing the SIEM/SOAR phase-out, phase-in approach.
  • Develop SOAR playbooks to provide case handling and Incident response as per triage needs
  • Creation of SOAR assets such as reports etc.
  • Guide on building or maturing cloud security programs
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SecOps Engineer
SecOps Engineer

Greytip Software Private Limited • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Google SecOps Engineer (SIEM & SOAR)
Google SecOps Engineer (SIEM & SOAR)

Tata Consultancy Services • Chennai District

On-site
INR 1,400,000 - 2,200,000
Sr IT Security Analyst SIEM SOAR
Sr IT Security Analyst SIEM SOAR

Technogen • Hyderabad

On-site
INR 4,500,000 - 7,500,000
Assistant Manager
Assistant Manager

WSNE Consulting Pvt. Ltd. • Mumbai

On-site
INR 1,400,000 - 1,800,000
Senior Google SecOps Engineer
Senior Google SecOps Engineer

Persistent Systems • Pune District

Hybrid
INR 2,800,000 - 4,200,000
Group term life insurance
Personal accident insurance
Mediclaim hospitalization
+2
XSOAR Engineer - Consultant (Mumbai)
XSOAR Engineer - Consultant (Mumbai)

Embark • Thane

On-site
INR 700,000 - 1,100,000
Senior Google SecOps Engineer
Senior Google SecOps Engineer

Persistent • Pune District

Hybrid
INR 1,800,000 - 2,600,000
Competitive salary
Career development & certifications
Flexible work hours
+2
SOAR Engineer
SOAR Engineer

Embarkgcc Services • Mumbai

On-site
INR 1,000,000 - 1,800,000
L2 SOC Security Engineer (SIEM / SOAR / UEBA) 3 to 4 Years
L2 SOC Security Engineer (SIEM / SOAR / UEBA) 3 to 4 Years

Black Box • Gurugram District

On-site
INR 600,000 - 1,000,000
SIEM & SOAR Security Architect
SIEM & SOAR Security Architect

Huxley • India

On-site
INR 420,000 - 700,000