Sr IT Security Analyst SIEM SOAR

Technogen

Hyderabad

Hybrid

INR 4,500,000 - 7,500,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Technogen is seeking a Senior SIEM Security Engineer in Hyderabad to architect, implement, and optimize enterprise SIEM, NDR, and XDR deployments. You will develop detection content, onboard log sources, and coordinate with SOC and IR teams to improve alert fidelity and response efficiency.

The role requires strong scripting, cloud detection expertise, and experience with major SIEM/SOAR platforms. You will drive automation, dashboards, and documentation to support secure, scalable operations in

Qualifications

  • Security engineering and SOC architecture in an enterprise environment.
  • Experience with SIEM platforms and automation tools is required.
  • Knowledge of cloud detection across Azure, AWS, or GCP is essential.

Responsibilities

  • Architect, implement, and maintain SIEM infrastructure for reliable log ingestion, parsing, correlation, and alerting.
  • Develop and fine-tune detection content and analytics rules for endpoints, networks, and cloud.
  • Manage and enhance NDR and XDR platforms, integrating telemetry for end-to-end visibility.
  • Collaborate with SOC and Incident Response to improve alert fidelity and investigation workflows.
  • Integrate SIEM with SOAR and automation pipelines for rapid response and consistent case handling.
  • Coordinate with infrastructure and application teams for comprehensive log coverage and data retention compliance.
  • Develop and maintain dashboards, metrics, and reporting to measure detection performance.
  • Conduct periodic health checks, tuning, and performance optimization for SIEM and NDR solutions.
  • Maintain documentation, playbooks, and SOPs supporting SIEM and NDR operations.

Skills

Security engineering
Detection engineering
SOC architecture
Python scripting
PowerShell scripting
Bash scripting
MITRE ATT&CK
D3FEND framework
Log onboarding
SOAR automation
NDR/XDR
Cloud detection
Data normalization
Threat hunting
Communication
Analytical skills

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Splunk
XSOAR
ExtraHop
Vectra
Cisco
CrowdStrike
Sentinel

Job description

Roles and Responsibilities
  • Architect, implement, and maintain SIEM infrastructure to ensure reliable log ingestion, parsing, correlation, and alerting across enterprise systems.
  • Develop and fine-tune detection content and analytics rules to identify suspicious or malicious activity across endpoints, networks, and cloud environments.
  • Manage and enhance Network Detection and Response (NDR) and Extended Detection and Response (XDR) platforms, integrating telemetry for end-to-end visibility.
  • Partner with the SOC and Incident Response teams to improve alert fidelity, reduce false positives, and accelerate investigation workflows.
  • Integrate SIEM with SOAR and automation pipelines to support rapid response and consistent case handling.
  • Collaborate with infrastructure and application teams to ensure comprehensive log coverage and compliance with data retention and privacy requirements.
  • Develop and maintain dashboards, metrics, and reporting to measure detection performance and operational efficiency.
  • Conduct periodic health checks, tuning, and performance optimization for SIEM and NDR solutions.
  • Maintain detailed documentation, playbooks, and SOPs supporting SIEM and NDR operations.
Skills and Qualifications
Required:
  • 58 years of experience in security engineering, detection engineering, or SOC architecture in an enterprise environment.
  • Expert-level knowledge of SIEM platforms (e.g., Splunk, XSOAR, or equivalent), including onboarding, parsing, rule creation, and optimization.
  • Strong understanding of detection engineering, including attack chain mapping, MITRE ATT&CK coverage, and event correlation.
  • Experience with log source onboarding (firewalls, proxies, endpoints, cloud, identity, email systems etc.).
  • Familiarity with SOAR tools and automation workflows for triage and enrichment.
  • Strong scripting skills (Python, PowerShell, or Bash) for rule automation, parsing, and enrichment.
  • Understanding of cloud detection engineering across Azure, AWS, or GCP environments.
  • Excellent analytical, problem-solving, and communication skills, with a focus on collaboration and data‑driven decision‑making.
  • SIEM engineering and administration (Splunk, Sentinel, etc.)
  • Log collection, parsing, and correlation logic development
  • NDR/XDR deployment and tuning (e.g., ExtraHop, Vectra, Cisco, CrowdStrike, or similar)
  • Detection engineering and content lifecycle management
  • Cloud detection coverage (Azure, AWS, GCP)
  • Scripting and automation (Python, PowerShell, Bash)
  • SOAR integration for alert enrichment and response automation
  • Data normalization, threat hunting, and query development
  • Familiarity with the MITRE ATT&CK and D3FEND frameworks
  • Network security, endpoint telemetry, and identity-based detection techniques
Preferred:
  • Bachelor’s degree in Cybersecurity, Computer Science, or related technical field, or equivalent professional experience.
  • Demonstrated success designing, scaling, and maintaining enterprise SIEM and detection systems.
  • Certifications such as GIAC Certified Detection Analyst (GCDA), GIAC Security Operations Certified (GSOC), CompTIA CySA+, ISC2 SSCP, Splunk Enterprise Security Certified Admin or Architect, or equivalent detection engineering or SIEM certification
  • Analytical and detail-oriented with a focus on precision and reliability
  • Strong communication and collaboration across technical and non-technical stakeholders
  • Adaptable and proactive in a fast‑paced, global environment
  • Passion for continuous learning, innovation, and automation in security operations
  • Effective mentor and team contributor
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Sr. Consultant
Sr. Consultant

Tribastion Technologies Pvt. Ltd. • India

On-site
INR 1,000,000 - 1,500,000
Associate SOC Analyst
Associate SOC Analyst

ISA • Maharashtra

On-site
INR 600,000 - 1,000,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Soc Engineer
Soc Engineer

HCLTech • Jigani

Hybrid
INR 1,200,000 - 2,400,000
Senior SOC Analyst
Senior SOC Analyst

DMart • Thane

On-site
INR 900,000 - 1,300,000
Security Analyst
Security Analyst

Access Healthcare • Zone 7 Ambattur

On-site
INR 1,200,000 - 2,100,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Siem Engineer
Siem Engineer

Tata Consultancy Services • Ernakulam

On-site
INR 1,500,000 - 3,000,000
Security Operations (SecOps) Engineer
Security Operations (SecOps) Engineer

ECLAT Health Solutions • Hyderabad

On-site
INR 800,000 - 1,500,000