Get more replies from employers
Send a job-specific resume in minutes.
Tata Consultancy Services in Hyderabad is seeking a highly skilled Google Chronicle SIEM Engineer with expertise in SOC automation to enhance our detection capabilities and reduce false positives across the security landscape.
The ideal candidate will be responsible for designing, developing, and maintaining advanced detection use cases, automation workflows, and integrations to strengthen our overall security posture and improve operational efficiency within the SOC environment.
Interview Mode: Virtual Interview (13-Aug)
Job Description:
We are seeking a highly skilled Google Chronicle SIEM Engineer with expertise in SOC automation to enhance our detection capabilities and reduce false positives across the security landscape. The ideal candidate will be responsible for designing, developing, and maintaining advanced detection use cases, automation workflows, and integrations to strengthen our overall security posture and improve operational efficiency within the SOC environment.
Design, implement, and optimize Google Chronicle SIEM for scalable log ingestion, parsing, normalization, and enrichment.
Create and updating correlation rules and use cases
Develop and fine-tune detection rules, parsers, and correlation logic to improve threat detection accuracy.
Integrate diverse log sources including firewalls, endpoint security, cloud services, IAM, ,network devices and etc.,.
Build and maintain custom parsers and dashboards to enhance visibility into security events.
Collaborate with threat hunting and detection engineering teams to identify and implement new detection logic.
Design and implement automation workflows (SOAR-based or API-based) to reduce analyst workload and response time.
Automate alert triage, enrichment, and response actions using scripts, playbooks, or orchestration tools.
Integrate Google Chronicle with automation platforms (e.g., Cortex XSOAR, Splunk SOAR, Swimlane, or custom Python-based frameworks).
Deploy, configure, and manage Bind Plane agents across servers and cloud workloads.
Set up data ingestion from multiple sources (Windows, Linux, databases, firewalls, cloud services).
Normalize data schemas and forward logs to SIEM or observability tools (Chronicle, Elastic, Splunk).
Configure pipelines for log transformation, labeling, and enrichment.
Implement monitoring and alerts for agent health, performance, and log ingestion failures.