Soc Engineer

HCLTech

Jigani

Hybrid

INR 1,200,000 - 2,400,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

HCLTech in India is seeking a SOC Detection and Automation Engineer to design, implement, and maintain detection content within the SIEM, while driving automation for Level 1 incident triage and response. You will translate threat intel and MITRE ATT&CK techniques into actionable detection content and collaborate with the SOC team to improve coverage and reduce false positives.

You will develop automation playbooks, integrate SIEM with other security tools via APIs, and apply AI/ML capabilities

Qualifications

  • 3+ years of experience in Security Operations or Detection Engineering.
  • Proficiency in designing and implementing detection content using a SIEM/SOAR platform and content development.
  • Proficiency in scripting (Python/PowerShell) for automation and data manipulation.

Responsibilities

  • Design, develop, test, and deploy detection rules, correlational logic, and behavioral models within SIEM.
  • Translate threat intel and MITRE ATT&CK techniques into actionable detection content.
  • Continuously review and tune detection content to minimize false positives and maximize coverage of new threats.
  • Develop, implement, and maintain automation playbooks to automate Level 1 triage tasks and data enrichment.

Skills

SIEM/SOAR
Detection engineering
Python scripting
MITRE ATT&CK
Automation playbooks
API integrations
Cloud environments
Windows/Linux

Tools

XSIAM
Cortex XSOAR

Job description

SOC Detection and Automation Engineer

Overview

sible for enhancing our security posture by developing, implementing, and maintaining detection content within the SIEM. A key focus of this position will be leveraging our SIEMs automation and AI capabilities to streamline level 1 security incident triage and response, thereby increasing the efficiency and effectiveness of our Security Operations Center (SOC).

Responsibilities

We are seeking a highly skilled and motivated SOC Engineer to join our security operations team. This critical role will be respon

Detection Engineering and Content Development
  • Design, develop, test, and deploy high-fidelity detection rules, correlational logic, and behavioral models within SIEM.
  • Translate threat intelligence, known vulnerabilities, and observed attack techniques (e.g., MITRE ATT&CK framework) into actionable detection content.
  • Continuously review and tune existing detection content to minimize false positives while maximizing coverage of emerging threats.
  • Ensure all detection content is mapped to relevant security controls and incident response playbooks.
Automation and Efficiency
  • Develop, implement, and maintain automation playbooks (using our SIEMs automation engine) to automate repetitive Level 1 incident triage tasks, data enrichment, and initial response actions.
  • Integrate SIEM with other security tools and enterprise platforms via APIs and connectors to facilitate seamless data flow and automated response.
  • Explore and apply SIEMs built-in AI/ML capabilities to improve alert prioritization, anomaly detection, and automated incident clustering.
  • Document automation logic, workflows, and effectiveness metrics.
Platform Management and Optimization
  • Act as a subject matter expert for the SIEM, including data ingestion, logging policies, and platform health.
  • Collaborate with Security Architecture and IT teams to onboard new data sources into SIEM, ensuring proper normalization and parsing for detection use cases.
  • Monitor platform performance, troubleshoot content execution issues, and assist in maintaining the overall operational stability of the SIEM environment.
Collaboration and Improvement
  • Work closely with SOC Analysts, Threat Hunters, and Incident Responders to understand their needs and develop content that directly supports their operations.
  • Participate in post-incident review processes to identify detection and automation gaps and drive improvements.
  • Stay current with the latest cybersecurity trends, attack vectors, and SIEM features and updates.
Qualifications
Required Skills and Experience
  • 3+ years of experience in Security Operations, Threat Hunting, or Detection Engineering.
  • Demonstrable expertise in designing and implementing detection content using a SIEM/SOAR platform (strong preference for Palo Alto Networks XSIAM/Cortex XSOAR experience).
  • Deep understanding of the cyber kill chain and MITRE ATT&CK framework.
  • Proficiency in scripting languages (e.g., Python, PowerShell) for automation and data manipulation.
  • Strong knowledge of security logging formats, network protocols, operating systems (Windows, Linux), and cloud environments.
  • Experience with API integrations and developing automation playbooks (SOAR).
  • Excellent analytical, problem-solving, and communication skills.
Preferred Qualifications
  • Hands-on experience with Palo Alto Networks XSIAM, including content creation and automation development.
  • Relevant industry certifications (e.g., PCNSE, PCSAE, GCIH, GCFA, CISSP).
  • Experience with cloud security monitoring (AWS, Azure, GCP).
  • Familiarity with threat intelligence platforms and integrating intelligence feeds into detection logic.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Security Engineer II
Security Engineer II

SteerLean Consulting • Gurugram District

On-site
INR 1,800,000 - 2,400,000
Sr. Consultant
Sr. Consultant

Tribastion Technologies Pvt. Ltd. • India

On-site
INR 1,000,000 - 1,500,000
SOC Principal
SOC Principal

HCLSoftware • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Security Engineer II
Security Engineer II

Steerlean • Gurugram District

On-site
INR 1,800,000 - 2,400,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
SOC Engineer
SOC Engineer

Lonvec Technologies Private Limited • Chennai District

Hybrid
INR 900,000 - 1,200,000
Cyber Security Manager
Cyber Security Manager

Wsne Consulting • Mumbai

On-site
INR 1,000,000 - 1,800,000
Sr IT Security Analyst SIEM SOAR
Sr IT Security Analyst SIEM SOAR

Technogen • Hyderabad

Hybrid
INR 4,500,000 - 7,500,000
Associate SOC Analyst
Associate SOC Analyst

ISA • Maharashtra

On-site
INR 600,000 - 1,000,000