Job Description**
About Gurucul:
Gurucul is a global cyber security company that delivers a unified, cloud-native Security
Analytics and Operations Platform that includes Next-Gen SIEM, Open XDR, UEBA, and
Identity Analytics. Our mission is to help organizations protect their most valuable assets by detecting, predicting, and preventing threats through machine learning behavior profiling, real-
time analytics, and open data security frameworks. We serve Global 1000 enterprises and government agencies around the world.
JOB DESCRIPTION
Gurucul is seeking a motivated SIEM Implementation Engineer (3–5 years of experience)
to join our Professional Services team. The ideal candidate is passionate about security
analytics, hands-on engineering, and delivering exceptional customer experiences. You will
work directly with enterprise customers to implement, configure, and operationalize our
industry-leading SIEM solution. The role combines technical delivery, problem-solving,
customer interaction, and continuous improvement of SIEM capabilities.
This position requires strong fundamentals in SIEM technologies, log source integration,
detection engineering, and system troubleshooting across Linux/Windows environments.
Travel may be required for onsite engagements.
RESPONSIBILITIES
Implementation & Deployment
- Install, configure, and deploy Gurucul’s Next-Gen SIEM platform in customer
- environments (on-prem, cloud, hybrid).
- Integrate diverse log sources, ensuring proper parsing, normalization, and data
- quality.
- Configure data ingestion pipelines, connectors, agents, collectors, and parsing rules.
- Communicate technical concepts clearly to customers during workshops, onboarding calls, and deployment sessions.
- and best practices.
- Create implementation documentation, deployment guides, and runbooks.
- Customize and tune SIEM rules, dashboards, correlation logic, and behavioural
- models as per customer requirements.
- Perform data integrity checks and troubleshoot ingestion issues, missing fields, and
- Optimize platform performance, resource utilization, and ingestion throughput.
- Assist customers in implementing new use cases mapped to MITRE ATT&CK and
- industry threats.
- Build and refine dashboards, queries, correlation rules, and alerting logic.
- Support UEBA model validation and help reduce false positives by tuning logic and
- baselines.
Troubleshooting & Technical Expertise
- Troubleshoot SIEM platform issues on both Windows and Linux environments.
- Work with databases (MSSQL, MySQL) to validate ingestion, queries, and backend
- configurations.
- Collaborate with product and engineering teams for escalations or platform-related
- issues.
Training & Knowledge Transfer
- Conduct customer training sessions on SIEM features, log integrations, dashboards,
- reporting, and detection frameworks.
- Provide continuous guidance, best practices, and operational recommendations to
- customers.
Operational Deliverables
- Maintain up-to-date documentation including architecture diagrams, SOPs, and
- integration playbooks.
- Support pre-sales during POCs, demos, and technical deep dives when required.
- Ensure customer satisfaction through timely delivery, clear communication, and
EXPERIENCE
Candidates should have experience in the following:
- 3–5 years of hands-on experience implementing and supporting SIEM solutions (Gurucul, Splunk, QRadar, ArcSight, Sentinel, or similar).
- Strong understanding of log parsing, normalization, data pipelines, and data quality validation.
- Experience writing correlation rules, SQL queries, dashboards, and SIEM alert logic.
- Basic scripting in Python, PowerShell, or Shell for automation and troubleshooting.
- Understanding of MITRE ATT&CK Framework and common attack techniques.
- Familiarity with networking concepts, cyber security domains, and threat detection
- Experience working directly with enterprise customers in implementation or support
- roles.
- Good communication and documentation skills.
Preferred Skills (Good to Have)
- Exposure to Big Data components (Kafka, Elasticsearch, Hadoop).
- Knowledge of Identity Analytics, UEBA, or behavior analytics models.
- Experience with REST APIs, integration scripts, or automation frameworks.
EDUCATION
- Bachelor’s degree in computer science, Engineering, Information Security, or
- Security certifications such as Security+, CEH, GCIA, or vendor-specific SIEM certifications are a plus.
LOCATION / TRAVEL
Position is based in Pune, India. This role may require up to 20–30% travel for customer onsite implementation activities.