SME - Security Investigations, SIEM

HCL Technologies Limited

Pune District

Remote

INR 2,500,000 - 4,500,000

Full time

1 hour ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

HCLTech is seeking an experienced L3 Splunk detection engineer to lead development, tuning, and validation of security detections. You will translate threat intelligence into high-quality Splunk content and collaborate across SOC, IR, threat hunting, CTI, IAM/PAM, cloud, and network teams.

The role emphasizes correlation searches, dashboards, and automation, with mentoring of L2 analysts and a focus on data quality and detection coverage. Offshore India location applies.

Qualifications

  • 10+ years of experience in SIEM engineering or detection engineering.
  • Expert-level Splunk skills including SPL, CIM, macros, and dashboards.
  • Experience with MITRE ATT&CK mapping and threat detection content.

Responsibilities

  • Develop, tune, validate, and improve Splunk-based detections.
  • Collaborate with SOC, IR, and threat-hunting teams to reduce alert noise.
  • Automate deployment, testing, and content validation.

Skills

Splunk SPL
Python
CI/CD
Git
Threat detection
Telemetries onboarding
Communication
Leadership
Problem solving
Automation

Education

Bachelor’s degree in computer science/ IT
University degree in IT or IT Security

Tools

Splunk Enterprise Security
Splunk Cloud
KQL / EQL / Sigma

Job description

Division Cybersecurity- AppSec Track SOC- Detection Engineering Level L3 Location Offshore (India) Years of Experience

  • 10+ years of experience in SIEM engineering, Splunk content development, detection engineering, SOC analytics, or threat-detection use cases.
  • Responsibilities Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content.
  • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high‑quality Splunk detections and analytics.
  • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise.
  • Design and develop correlation searches, risk‑based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk.
  • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement.
  • Map detections to MITRE ATT&CK; techniques, Client threat scenarios, control objectives, and relevant assets or business services.
  • Analyze false positives, missed detections, alert quality, detection gaps, and data‑quality issues; implement tuning recommendations through approved change processes.
  • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics.
  • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection.
  • Maintain the detection/use‑case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics.
  • Automate detection deployment, testing, version control, and content quality checks where feasible.
  • Mentor L2 analysts and provide technical reviews for detection‑content changes.
  • Technical Requirements Expert‑level Splunk Search Processing Language, correlation searches, Enterprise Security, risk‑based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards.
  • Strong experience with Splunk Cloud and enterprise‑scale security content engineering.
  • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security‑control platforms.
  • Deep knowledge of MITRE ATT&CK;, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks.
  • Experience with detection‑as‑code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation.
  • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability.
  • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections.
  • Understanding of SOC workflows, incident response, threat hunting, false‑positive management, and detection‑performance metrics.
  • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred.
  • Soft Skills Excellent communication and presentation skills.
  • Soft Skills Strong problem‑solving and critical thinking skills.
  • Soft Skills Exceptional project management and organizational abilities.
  • Soft Skills Team collaboration and leadership skills.
  • Soft Skills Client‑focused approach with a commitment to delivering exceptional customer service.
  • Certifications (Good to have) Good to have relevant certificates like (any of the below):
  • Splunk Enterprise Security Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Certified Admin.
  • GCIA, GCIH, GMON, CISSP, CySA+, or equivalent detection/security‑operations certification is preferred.
  • Educational Qualifications University degree in IT or/and IT Security.
  • Educational Qualifications Bachelor’s degree in computer science/ IT or any relevant fields.
Key Responsibilities

Division Cybersecurity- AppSec Track SOC- Detection Engineering Level L3 Location Offshore (India) Years of Experience

  • 10+ years of experience in SIEM engineering, Splunk content development, detection engineering, SOC analytics, or threat‑detection use cases.
  • Responsibilities Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content.
  • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high‑quality Splunk detections and analytics.
  • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise.
  • Design and develop correlation searches, risk‑based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk.
  • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement.
  • Map detections to MITRE ATT&CK; techniques, Client threat scenarios, control objectives, and relevant assets or business services.
  • Analyze false positives, missed detections, alert quality, detection gaps, and data‑quality issues; implement tuning recommendations through approved change processes.
  • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics.
  • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection.
  • Maintain the detection/use‑case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics.
  • Automate detection deployment, testing, version control, and content quality checks where feasible.
  • Mentor L2 analysts and provide technical reviews for detection‑content changes.
  • Technical Requirements Expert‑level Splunk Search Processing Language, correlation searches, Enterprise Security, risk‑based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards.
  • Strong experience with Splunk Cloud and enterprise‑scale security content engineering.
  • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security‑control platforms.
  • Deep knowledge of MITRE ATT&CK;, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks.
  • Experience with detection‑as‑code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation.
  • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability.
  • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections.
  • Understanding of SOC workflows, incident response, threat hunting, false‑positive management, and detection‑performance metrics.
  • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred.
  • Soft Skills Excellent communication and presentation skills.
  • Soft Skills Strong problem‑solving and critical thinking skills.
  • Soft Skills Exceptional project management and organizational abilities.
  • Soft Skills Team collaboration and leadership skills.
  • Soft Skills Client‑focused approach with a commitment to delivering exceptional customer service.
  • Certifications (Good to have) Good to have relevant certificates like (any of the below):
  • Splunk Enterprise Security Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Certified Admin.
  • GCIA, GCIH, GMON, CISSP, CySA+, or equivalent detection/security‑operations certification is preferred.
  • Educational Qualifications University degree in IT or/and IT Security.
  • Educational Qualifications Bachelor’s degree in computer science/ IT or any relevant fields.
Skill Requirements

Division Cybersecurity- AppSec Track SOC- Detection Engineering Level L3 Location Offshore (India) Years of Experience

  • 10+ years of experience in SIEM engineering, Splunk content development, detection engineering, SOC analytics, or threat‑detection use cases.
  • Responsibilities Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content.
  • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high‑quality Splunk detections and analytics.
  • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise.
  • Design and develop correlation searches, risk‑based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk.
  • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement.
  • Map detections to MITRE ATT&CK; techniques, Client threat scenarios, control objectives, and relevant assets or business services.
  • Analyze false positives, missed detections, alert quality, detection gaps, and data‑quality issues; implement tuning recommendations through approved change processes.
  • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics.
  • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection.
  • Maintain the detection/use‑case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics.
  • Automate detection deployment, testing, version control, and content quality checks where feasible.
  • Mentor L2 analysts and provide technical reviews for detection‑content changes.
  • Technical Requirements Expert‑level Splunk Search Processing Language, correlation searches, Enterprise Security, risk‑based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards.
  • Strong experience with Splunk Cloud and enterprise‑scale security content engineering.
  • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security‑control platforms.
  • Deep knowledge of MITRE ATT&CK;, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks.
  • Experience with detection‑as‑code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation.
  • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability.
  • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections.
  • Understanding of SOC workflows, incident response, threat hunting, false‑positive management, and detection‑performance metrics.
  • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred.
  • Soft Skills Excellent communication and presentation skills.
  • Soft Skills Strong problem‑solving and critical thinking skills.
  • Soft Skills Exceptional project management and organizational abilities.
  • Soft Skills Team collaboration and leadership skills.
  • Soft Skills Client‑focused approach with a commitment to delivering exceptional customer service.
  • Certifications (Good to have) Good to have relevant certificates like (any of the below):
  • Splunk Enterprise Security Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Certified Admin.
  • GCIA, GCIH, GMON, CISSP, CySA+, or equivalent detection/security‑operations certification is preferred.
  • Educational Qualifications University degree in IT or/and IT Security.
  • Educational Qualifications Bachelor’s degree in computer science/ IT or any relevant fields.
Other Requirements

Division Cybersecurity- AppSec Track SOC- Detection Engineering Level L3 Location Offshore (India) Years of Experience

  • 10+ years of experience in SIEM engineering, Splunk content development, detection engineering, SOC analytics, or threat‑detection use cases.
  • Responsibilities Serve as an L3 Splunk-heavy detection engineer responsible for developing, tuning, validating, and improving Customer security detection content.
  • Translate threat intelligence, incidents, attack techniques, control gaps, and security requirements into high‑quality Splunk detections and analytics.
  • Work with SOC, incident response, threat hunting, CTI, IAM/PAM, cloud, endpoint, network, and application teams to improve detection coverage and reduce alert noise.
  • Design and develop correlation searches, risk‑based alerts, dashboards, analytic stories, reports, and investigation searches in Splunk.
  • Maintain the detection lifecycle, including requirements, data validation, development, testing, tuning, deployment, documentation, review, and retirement.
  • Map detections to MITRE ATT&CK; techniques, Client threat scenarios, control objectives, and relevant assets or business services.
  • Analyze false positives, missed detections, alert quality, detection gaps, and data‑quality issues; implement tuning recommendations through approved change processes.
  • Support security incident investigations and threat hunts by creating complex searches, enrichment logic, and reusable analytics.
  • Validate that required log sources, fields, data models, timestamps, and context are available and reliable for each detection.
  • Maintain the detection/use‑case catalogue, tuning history, validation evidence, testing outcomes, and coverage metrics.
  • Automate detection deployment, testing, version control, and content quality checks where feasible.
  • Mentor L2 analysts and provide technical reviews for detection‑content changes.
  • Technical Requirements Expert‑level Splunk Search Processing Language, correlation searches, Enterprise Security, risk‑based alerting, data models, CIM, macros, lookups, accelerated searches, and dashboards.
  • Strong experience with Splunk Cloud and enterprise‑scale security content engineering.
  • Experience onboarding and validating telemetry from endpoint, identity, PAM, cloud, network, email, application, database, and security‑control platforms.
  • Deep knowledge of MITRE ATT&CK;, threat detection methodologies, attacker behavior, cyber kill chain, and common detection frameworks.
  • Experience with detection‑as‑code, Git, CI/CD, unit testing, content validation, Python, REST APIs, and automation.
  • Ability to analyze data quality, field normalization, sourcetypes, index strategy, parsing, latency, and ingestion reliability.
  • Experience integrating threat intelligence, asset context, identity context, vulnerability data, and business criticality into detections.
  • Understanding of SOC workflows, incident response, threat hunting, false‑positive management, and detection‑performance metrics.
  • Knowledge of Sigma, YARA, KQL, EQL, or other detection languages is preferred.
  • Soft Skills Excellent communication and presentation skills.
  • Soft Skills Strong problem‑solving and critical thinking skills.
  • Soft Skills Exceptional project management and organizational abilities.
  • Soft Skills Team collaboration and leadership skills.
  • Soft Skills Client‑focused approach with a commitment to delivering exceptional customer service.
  • Certifications (Good to have) Good to have relevant certificates like (any of the below):
  • Splunk Enterprise Security Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Certified Admin.
  • GCIA, GCIH, GMON, CISSP, CySA+, or equivalent detection/security‑operations certification is preferred.
  • Educational Qualifications University degree in IT or/and IT Security.
  • Educational Qualifications Bachelor’s degree in computer science/ IT or any relevant fields.

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry‑leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8billion.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SME - Security Analysis, SIEM
SME - Security Analysis, SIEM

HCL Technologies Limited • Pune District

Remote
INR 2,500,000 - 4,000,000
Analyst (Support & Operations)
Analyst (Support & Operations)

HCL Technologies Limited • Dadri

On-site
INR 800,000 - 1,600,000
SME - Qualys
SME - Qualys

HCL Technologies Limited • Dadri

On-site
INR 1,500,000 - 2,000,000
Senior Engineer - Desk Side Services, AMT Asset Management Software
Senior Engineer - Desk Side Services, AMT Asset Management Software

HCL Technologies Limited • Gurugram District

On-site
INR 600,000 - 800,000
Track Manager - Cisco Identity Services Engine (ISE)
Track Manager - Cisco Identity Services Engine (ISE)

HCL Technologies Limited • Pune District

On-site
INR 1,200,000 - 2,500,000
Senior Technical Support Specialist
Senior Technical Support Specialist

HCL Technologies Limited • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Subject Matter Expert (Support&Ops)
Subject Matter Expert (Support&Ops)

HCL Technologies Limited • Dadri

On-site
INR 2,500,000 - 4,000,000
Track Lead - Saviynt, Java
Track Lead - Saviynt, Java

HCL Technologies Limited • Hyderabad

Hybrid
INR 4,000,000 - 7,000,000
SME - IAM Service Delivery
SME - IAM Service Delivery

HCL Technologies Limited • Dadri

On-site
INR 600,000 - 1,000,000
Track Lead - CheckPoint PPC (Software), Cloud Security
Track Lead - CheckPoint PPC (Software), Cloud Security

HCL Technologies Limited • Gurugram District

Hybrid
INR 2,500,000 - 3,500,000