TECHNICAL LEAD - Elastic Search

Happiest Minds Technologies

Bengaluru

On-site

INR 2,500,000 - 4,000,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Happiest Minds Technologies in Bengaluru, India, seeks an experienced SOC L3 professional with deep Elastic SIEM and SOAR expertise. The role focuses on SIEM deployments, content engineering, threat hunting, and incident response across multiple platforms including Elastic Security and other major SIEMs.

You will lead complex investigations, build detections and dashboards, and mentor junior analysts while participating in SOC transformation and platform evaluations.

Qualifications

  • 6-10+ years of security operations experience.
  • Hands-on in SIEM implementation, administration and content engineering.
  • Experience with multiple SIEM platforms (Elastic, MS Sentinel, QRadar, etc).

Responsibilities

  • Lead L3 investigations for complex security incidents.
  • Design, implement and optimize Elastic SIEM deployments.
  • Develop and maintain SOAR playbooks and automations.
  • Build and tune detection rules, dashboards and alerts.
  • Assist in onboarding log sources and data pipelines.
  • Mentor L1/L2 analysts and guide incident response activities.
  • Integrate threat intel feeds to improve detection maturity.
  • Contribute to SOC transformation and platform evaluations.

Skills

Elastic SIEM
SOAR
Threat hunting
Incident response
L3 investigations
Automation scripting

Tools

Elastic Defend
Kibana
Elasticsearch
Logstash
Beats
Fleet
Microsoft Sentinel
QRadar
Splunk

Job description

Job Description - SOC L3 Engineer (Elastic SIEM & SOAR)
Location: Bengaluru / India
Experience: 6-10+ Years
Role: SOC L3 / Senior Security Operations Engineer
Role Summary

Seeking an experienced SOC L3 professional with strong expertise in Elastic Security (SIEM) and SOAR platforms. The candidate should possess hands-on experience in SIEM implementation, administration, content engineering, threat hunting, incident response, and SOC optimization across multiple SIEM technologies such as Microsoft Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic, or similar platforms.

Key Responsibilities
  • Lead L3 investigations for complex security incidents and advanced threats.
  • Design, implement, and optimize Elastic SIEM and Elastic Security deployments.
  • Develop and maintain SOAR playbooks, automation workflows, and integrations.
  • Build and tune detection rules, correlation logic, dashboards, alerts, and threat hunting content.
  • Support end-to-end SIEM implementation including onboarding log sources, parsing, normalization, and data pipelines.
  • Perform threat hunting, malware analysis, and root cause investigations.
  • Provide technical guidance to L1/L2 analysts and lead incident response activities.
  • Integrate threat intelligence feeds and improve detection maturity.
  • Conduct use case development, validation, and security monitoring enhancements.
  • Participate in SOC transformation, SIEM migrations, and platform evaluations.
Required Technical Skills
  • Strong hands-on experience with Elastic SIEM / Elastic Security.
  • Experience with Elastic Defend, Kibana, Elasticsearch, Logstash, Beats, Fleet, and detection engineering.
  • Hands-on experience in SOAR implementation and automation orchestration.
  • Experience implementing or managing other SIEM platforms such as Microsoft Sentinel, QRadar, Splunk, FortiSIEM, ArcSight, Sumo Logic, Stellar Cyber, or equivalent.
  • Strong understanding of Windows, Linux, Active Directory, Azure, AWS, networking, and cloud security.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, IOC analysis, and threat intelligence.
  • Experience with scripting (Python, PowerShell, Bash) for automation.
  • Understanding of EDR/XDR, NDR, Email Security, IAM, and Security Controls integration.
Preferred Certifications

Elastic Certified Engineer, Microsoft SC-200, AZ-500, Splunk, QRadar, GCIH, GCIA, CEH, CISSP, or equivalent certifications.

Soft Skills

Strong analytical and troubleshooting skills, stakeholder communication, client-facing experience, documentation skills, mentoring capability, and ability to lead critical security incidents.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)
Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)

IT MNC • Karnataka

On-site
INR 1,500,000 - 2,000,000
L3 Engineer
L3 Engineer

Happiest Minds Technologies • Bengaluru

On-site
INR 1,200,000 - 2,500,000
SOC L3 Engineer (Elastic SIEM & SOAR)
SOC L3 Engineer (Elastic SIEM & SOAR)

Happiest Minds Technologies • Dadri, Pune District, Bengaluru

On-site
INR 1,400,000 - 2,100,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Security Architect
Security Architect

Accenture in India • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Sr IT Security Analyst SIEM SOAR
Sr IT Security Analyst SIEM SOAR

Technogen • Hyderabad

On-site
INR 4,500,000 - 7,500,000
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner

Innova ESI • Mumbai

On-site
INR 800,000 - 1,200,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Technology Specialist - SOC-L2
Technology Specialist - SOC-L2

SHI • Hyderabad

On-site
INR 800,000 - 1,200,000
Senior Consultant-SOC L3-SIEM Engineering | Experience: 5+ Years
Senior Consultant-SOC L3-SIEM Engineering | Experience: 5+ Years

Aujas Networks Pvt. Ltd. • Bengaluru, Gurugram District, Mumbai

On-site
INR 1,200,000 - 1,500,000