Sr. Consultant

Tribastion Technologies Pvt. Ltd.

India

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

A leading cybersecurity firm in India is seeking a SOC Detection & Platform Engineer responsible for developing high-quality security detections while ensuring the efficiency of SIEM/SOAR platforms. The role requires 4–8 years of experience, with hands-on expertise in SIEM tools like Splunk and strong proficiency in query languages. Candidates should also possess strong cybersecurity knowledge and skills in automation scripting. Join us to enhance our Security Operations Center and contribute to proactive security measures.

Qualifications

  • 4–8 years of SOC, detection engineering, or SIEM/SOAR experience.
  • Hands-on expertise with SIEM tools such as Sentinel, Splunk, Elastic, or QRadar.
  • Proficiency with query languages (KQL, SPL, SQL, etc.).
  • Strong understanding of cybersecurity principles and threat actor behaviors.
  • Experience with automation scripting (Python, PowerShell, Bash).
  • Familiarity with log pipelines and normalization concepts.

Responsibilities

  • Develop and maintain security detection use cases aligned with MITRE ATT&CK.
  • Design and implement correlation rules and alert logic across log sources.
  • Validate detection coverage through attack simulation and emulation activities.
  • Collaborate with teams to enhance detection effectiveness.
  • Manage and optimize SIEM/SOAR platforms for availability and performance.
  • Develop and maintain SOAR playbooks and automation workflows.

Skills

SOC experience
SIEM tools
Query languages proficiency
Cybersecurity principles
Automation scripting
Log normalization concepts

Tools

Sentinel
Splunk
Elastic
QRadar

Job description

The SOC Detection & Platform Engineer is responsible for developing high-quality security detections and ensuring the stability, scalability, and efficiency of the organization’s SIEM/SOAR platforms. This role combines advanced detection engineering with hands‑on platform operations to support a mature and proactive Security Operations Center (SOC).

Key Responsibilities – Detection Engineering
  • Develop, enhance, and maintain security detection use cases aligned with the MITRE ATT&CK framework.
  • Design and implement correlation rules, behavioral analytics, and alert logic across various log sources.
  • Perform false positive reduction, threshold optimization, and tuning of detection logic.
  • Validate detection coverage through attack simulation and adversary emulation activities.
  • Maintain documentation including rule logic, mapping, and use‑case repositories.
  • Collaborate with Threat Intelligence and SOC teams to enhance detection effectiveness.
  • Manage and optimize SIEM/SOAR platforms for availability and performance.
  • Handle log onboarding, parsing, normalization, enrichment, and schema alignment.
  • Maintain stable data pipelines including ingestion, indexing, and retention.
  • Integrate new log sources across endpoint, network, cloud, and application environments.
  • Develop and maintain SOAR playbooks and automation workflows.
  • Conduct platform health checks and configuration audits.
  • Work with cross‑functional teams to improve SOC visibility and detection maturity.
  • Support platform upgrades and capability enhancements.
  • Participate in threat‑hunting and purple‑team exercises.
  • Ensure compliance with documentation and change management processes.
Required Skills & Experience
  • 4–8 years of SOC, detection engineering, or SIEM/SOAR experience.
  • Hands‑on expertise with SIEM tools such as Sentinel, Splunk, Elastic, or QRadar.
  • Proficiency with query languages (KQL, SPL, SQL, etc.).
  • Strong understanding of cybersecurity principles and threat actor behaviors.
  • Experience with automation scripting (Python, PowerShell, Bash).
  • Familiarity with log pipelines and normalization concepts.
Preferred Qualifications
  • Experience with Detection‑as‑Code (Sigma).
  • Exposure to cloud security (Azure, AWS, GCP).
  • Experience with attack simulation tools (Atomic Red Team, Caldera).
  • Understanding of SIEM data engineering processes.
  • Strong analytical and problem‑solving skills.
  • Ability to work in fast‑paced environments.
  • High attention to detail and focus on operational excellence.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Soc Analyst
Soc Analyst

PwC India • Bengaluru

On-site
INR 1,400,000 - 2,200,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
DART Engineer
DART Engineer

HCLSoftware • Bengaluru

On-site
INR 1,500,000 - 2,100,000
SOC Principal
SOC Principal

HCLSoftware • Bengaluru

On-site
INR 4,500,000 - 7,500,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
SIEM & Detection Engineering Specialist
SIEM & Detection Engineering Specialist

Lonvec Technologies Private Limited • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Sr. SOC Analyst
Sr. SOC Analyst

Systems Plus Pvt. Ltd. • Pune District

On-site
INR 1,800,000 - 3,200,000
SOC Engineer
SOC Engineer

Lonvec Technologies Private Limited • Chennai District

On-site
INR 900,000 - 1,200,000
Sr SUPPORT ENGINEER - Cyber Security
Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 800,000 - 1,500,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000