Sr. Consultant

Tribastion Technologies Pvt. Ltd.

India

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading cybersecurity firm in India is seeking a SOC Detection & Platform Engineer responsible for developing high-quality security detections while ensuring the efficiency of SIEM/SOAR platforms. The role requires 4–8 years of experience, with hands-on expertise in SIEM tools like Splunk and strong proficiency in query languages. Candidates should also possess strong cybersecurity knowledge and skills in automation scripting. Join us to enhance our Security Operations Center and contribute to proactive security measures.

Qualifications

  • 4–8 years of SOC, detection engineering, or SIEM/SOAR experience.
  • Hands-on expertise with SIEM tools such as Sentinel, Splunk, Elastic, or QRadar.
  • Proficiency with query languages (KQL, SPL, SQL, etc.).
  • Strong understanding of cybersecurity principles and threat actor behaviors.
  • Experience with automation scripting (Python, PowerShell, Bash).
  • Familiarity with log pipelines and normalization concepts.

Responsibilities

  • Develop and maintain security detection use cases aligned with MITRE ATT&CK.
  • Design and implement correlation rules and alert logic across log sources.
  • Validate detection coverage through attack simulation and emulation activities.
  • Collaborate with teams to enhance detection effectiveness.
  • Manage and optimize SIEM/SOAR platforms for availability and performance.
  • Develop and maintain SOAR playbooks and automation workflows.

Skills

SOC experience
SIEM tools
Query languages proficiency
Cybersecurity principles
Automation scripting
Log normalization concepts

Tools

Sentinel
Splunk
Elastic
QRadar

Job description

The SOC Detection & Platform Engineer is responsible for developing high-quality security detections and ensuring the stability, scalability, and efficiency of the organization’s SIEM/SOAR platforms. This role combines advanced detection engineering with hands‑on platform operations to support a mature and proactive Security Operations Center (SOC).

Key Responsibilities – Detection Engineering
  • Develop, enhance, and maintain security detection use cases aligned with the MITRE ATT&CK framework.
  • Design and implement correlation rules, behavioral analytics, and alert logic across various log sources.
  • Perform false positive reduction, threshold optimization, and tuning of detection logic.
  • Validate detection coverage through attack simulation and adversary emulation activities.
  • Maintain documentation including rule logic, mapping, and use‑case repositories.
  • Collaborate with Threat Intelligence and SOC teams to enhance detection effectiveness.
  • Manage and optimize SIEM/SOAR platforms for availability and performance.
  • Handle log onboarding, parsing, normalization, enrichment, and schema alignment.
  • Maintain stable data pipelines including ingestion, indexing, and retention.
  • Integrate new log sources across endpoint, network, cloud, and application environments.
  • Develop and maintain SOAR playbooks and automation workflows.
  • Conduct platform health checks and configuration audits.
  • Work with cross‑functional teams to improve SOC visibility and detection maturity.
  • Support platform upgrades and capability enhancements.
  • Participate in threat‑hunting and purple‑team exercises.
  • Ensure compliance with documentation and change management processes.
Required Skills & Experience
  • 4–8 years of SOC, detection engineering, or SIEM/SOAR experience.
  • Hands‑on expertise with SIEM tools such as Sentinel, Splunk, Elastic, or QRadar.
  • Proficiency with query languages (KQL, SPL, SQL, etc.).
  • Strong understanding of cybersecurity principles and threat actor behaviors.
  • Experience with automation scripting (Python, PowerShell, Bash).
  • Familiarity with log pipelines and normalization concepts.
Preferred Qualifications
  • Experience with Detection‑as‑Code (Sigma).
  • Exposure to cloud security (Azure, AWS, GCP).
  • Experience with attack simulation tools (Atomic Red Team, Caldera).
  • Understanding of SIEM data engineering processes.
  • Strong analytical and problem‑solving skills.
  • Ability to work in fast‑paced environments.
  • High attention to detail and focus on operational excellence.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
SIEM & Detection Engineering Specialist
SIEM & Detection Engineering Specialist

Lonvec Technologies Private Limited • Bengaluru

Hybrid
INR 1,800,000 - 2,600,000
Senior Security Engineer
Senior Security Engineer

UST • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Sr SOC Analyst - CyberAxis
Sr SOC Analyst - CyberAxis

Cyberaxislabs • Hyderabad

On-site
INR 1,200,000 - 1,800,000
SOC Engineer
SOC Engineer

Lonvec Technologies Private Limited • Chennai District

Hybrid
INR 900,000 - 1,200,000
SOC Specialist
SOC Specialist

METRO/MAKRO • Pune District

On-site
INR 4,000,000 - 7,000,000
Platform Engineer
Platform Engineer

Indian Institute of Technology Delhi (IIT Delhi) • Hyderabad

On-site
INR 1,200,000 - 1,800,000
SOC Manager
SOC Manager

Sisainfosec • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Associate SOC
Associate SOC

Publicis Groupe Holdings B.V • Gurugram District

On-site
INR 1,200,000 - 1,800,000