SME - Security Analysis, SIEM

HCL Technologies Limited

Pune District

On-site

INR 1,800,000 - 3,200,000

Full time

14 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

HCL Technologies Limited is seeking an L3 Splunk-heavy detection engineer to develop, tune, validate, and improve customer security detection content in Pune, India. You will translate threat intelligence and incident data into high-quality Splunk detections and analytics, collaborating with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams.

You will design and deploy correlation searches, dashboards, reports, and investigation searches while

Qualifications

  • Expert-level SPL, correlation searches, Enterprise Security, risk-based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards.
  • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security-control platforms.
  • Deep knowledge of MITRE ATT&CK, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks.
  • Experience with detection-as-code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation.
  • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability.
  • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections.
  • Understanding of SOC workflows, incident response, threat hunting, false-positive management, and detection-performance metrics.
  • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred.

Responsibilities

  • Design and develop correlation searches, risk-based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk.
  • Maintain the detection lifecycle: requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement.
  • Map detections to MITRE ATT&CK techniques, client threat scenarios, control objectives, and relevant assets or business services.
  • Analyze false positives, missed detections, alert quality, detection gaps, and data-quality issues; implement tuning recommendations through approved change processes.
  • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics.
  • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection.
  • Maintain the detection/use-case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics.
  • Automate detection deployment, testing, version control, and content quality checks where feasible.
  • Mentor L2 analysts and provide technical reviews for detection-content changes.

Skills

Splunk SPL
Splunk Cloud
Security content engineering
MITRE ATT&CK mapping
Detection-as-code
Git & CI/CD
Python & REST APIs
Data quality & parsing

Tools

Git
CI/CD
Python
REST APIs

Job description

  • Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content.
  • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high-quality Splunk detections and analytics.
  • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise.
  • Design and develop correlation searches, risk-based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk.
  • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement.
  • Map detections to MITRE ATT&CK; techniques, Client threat scenarios, control objectives, and relevant assets or business services.
  • Analyze false positives, missed detections, alert quality, detection gaps, and data-quality issues; implement tuning recommendations through approved change processes.
  • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics.
  • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection.
  • Maintain the detection/use-case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics.
  • Automate detection deployment, testing, version control, and content quality checks where feasible.
  • Mentor L2 analysts and provide technical reviews for detection-content changes.
Key Responsibilities
  • Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content.
  • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high-quality Splunk detections and analytics.
  • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise.
  • Design and develop correlation searches, risk-based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk.
  • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement.
  • Map detections to MITRE ATT&CK; techniques, Client threat scenarios, control objectives, and relevant assets or business services.
  • Analyze false positives, missed detections, alert quality, detection gaps, and data-quality issues; implement tuning recommendations through approved change processes.
  • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics.
  • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection.
  • Maintain the detection/use-case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics.
  • Automate detection deployment, testing, version control, and content quality checks where feasible.
  • Mentor L2 analysts and provide technical reviews for detection-content changes.
Skill Requirements

Expert-level Splunk Search Processing Language, correlation searches, Enterprise Security, risk-based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards.

  • Strong experience with Splunk Cloud and enterprise-scale security content engineering.
  • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security-control platforms.
  • Deep knowledge of MITRE ATT&CK;, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks.
  • Experience with detection-as-code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation.
  • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability.
  • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections.
  • Understanding of SOC workflows, incident response, threat hunting, false-positive management, and detection-performance metrics.
  • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred.
Other Requirements
  • Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content.
  • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high-quality Splunk detections and analytics.
  • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise.
  • Design and develop correlation searches, risk-based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk.
  • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement.
  • Map detections to MITRE ATT&CK; techniques, Client threat scenarios, control objectives, and relevant assets or business services.
  • Analyze false positives, missed detections, alert quality, detection gaps, and data-quality issues; implement tuning recommendations through approved change processes.
  • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics.
  • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection.
  • Maintain the detection/use-case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics.
  • Automate detection deployment, testing, version control, and content quality checks where feasible.
  • Mentor L2 analysts and provide technical reviews for detection-content changes.

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026totaled $14.8billion.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Administrator (Support & Operations)
Administrator (Support & Operations)

HCL Technologies Limited • Greater Noida

On-site
INR 1,200,000 - 2,400,000
Administrator (Tools & Automation)
Administrator (Tools & Automation)

HCL Technologies Limited • Chennai District

On-site
INR 1,500,000 - 1,900,000
Sr Administrator (Support & Operations)
Sr Administrator (Support & Operations)

HCL Technologies Limited • Greater Noida

On-site
INR 800,000 - 1,200,000
Senior Track Lead
Senior Track Lead

HCL Technologies Limited • Navi Mumbai

On-site
INR 1,400,000 - 2,000,000
Security Operations Engineer
Security Operations Engineer

Pure Storage India Pvt Ltd • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Technical Lead
Senior Technical Lead

HCL Technologies Limited • Hyderabad

On-site
INR 1,800,000 - 2,800,000
Sr. Security Engineer
Sr. Security Engineer

Hitachi Vantara Corporation • New Delhi

On-site
INR 1,200,000 - 2,400,000
Customer Experience Splunk Technical Leader
Customer Experience Splunk Technical Leader

123 Cisco Systems (India) Private Limited • Mumbai

Hybrid
INR 900,000 - 1,400,000
Senior Threat Hunting And Incident Response Engineer
Senior Threat Hunting And Incident Response Engineer

Snowbit by Coralogix • Gurugram District

On-site
INR 2,500,000 - 6,000,000
SIEM Content Developer
SIEM Content Developer

Persistent Systems • Pune District

Hybrid
INR 3,000,000 - 6,000,000