Track Lead - Security Analysis, SIEM

HCL Technologies Limited

Lucknow

On-site

INR 2,500,000 - 4,000,000

Full time

18 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

HCL Technologies Limited in Lucknow seeks an experienced Threat Hunter to proactively identify, investigate, and mitigate advanced cyber threats that bypass standard controls. You will conduct hypothesis-based hunting across endpoints, networks, identity, and cloud to improve detection maturity.

Develop MITRE ATT&CK-aligned hunting hypotheses and convert findings into security incidents, detection rules, or change requests. Collaboration with SOC, IR, and Threat Intelligence teams is essential.

Qualifications

  • 6+ years in SOC / Threat Detection
  • 2+ years in threat hunting
  • Strong analytical and investigative mindset
  • Client facing reporting and presentation skills
  • Willingness to work in 24x7 SOC environments

Responsibilities

  • Conduct hypothesis-based threat hunting across endpoints, SIEM/Log Management, network telemetry, identity logs, and cloud platforms.
  • Identify stealthy and advanced threats including LotL techniques, APTs, lateral movement, privilege escalation, and insider indicators.
  • Develop and execute MITRE ATT&CK-aligned hunting hypotheses.
  • Convert hunting findings into security incidents, new detection rules, or change/service requests.
  • Collaborate with SOC, Incident Response, and Threat Intelligence teams.
  • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated).

Skills

Threat hunting
Analytical mindset
Client reporting
24x7 SOC readiness

Tools

Splunk
Microsoft Sentinel
Chronicle
Palo Alto XSIAM
Microsoft XDR
CrowdStrike
SentinelOne
Palo Alto Cortex
KQL
SPL

Job description

Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.

Key Responsibilities
  • Conduct hypothesis-based and IOC-driven threat hunting across:
    • Endpoint (EDR/XDR)
    • SIEM / Log Management platforms
    • Network telemetry (NDR)
    • Identity logs (AD / Entra ID)
    • Cloud platforms (Azure, AWS, M365)
  • Identify stealthy and advanced threats, including:
    • Living off the Land (LotL) techniques
    • Advanced Persistent Threats (APTs)
    • Lateral movement and privilege escalation
    • Insider threat indicators
  • Develop and execute MITRE ATT&CK;-aligned hunting hypotheses
  • Convert hunting findings into:
    • Security incidents
    • New detection rules (SIEM / EDR / XDR)
    • Change or service requests (misconfigurations, logging gaps)
  • Collaborate with SOC, Incident Response, and Threat Intelligence teams
  • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated)
Skill Requirements

echnical Skills

  • Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM)
  • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex)
  • Proficiency in KQL / SPL / advanced hunting queries
  • Deep understanding of MITRE ATT&CK;- techniques and TTPs
  • Strong OS knowledge: Windows, Linux, macOS
  • Basic scripting skills (PowerShell / Python preferred)
  • Cloud security exposure (Azure, AWS, M365 Defender)

Experience & Soft Skills

  • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting
  • Strong analytical and investigative mindset
  • Client facing reporting and presentation skills
  • Willingness to work in 24x7 SOC environments
Other Requirements

Role Overview Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.

  • Conduct hypothesis-based and IOC-driven threat hunting across:
    • Endpoint (EDR/XDR)
    • SIEM / Log Management platforms
    • Network telemetry (NDR)
    • Identity logs (AD / Entra ID)
    • Cloud platforms (Azure, AWS, M365)
  • Identify stealthy and advanced threats, including:
    • Living off the Land (LotL) techniques
    • Advanced Persistent Threats (APTs)
    • Lateral movement and privilege escalation
    • Insider threat indicators
  • Develop and execute MITRE ATT&CK;-aligned hunting hypotheses
  • Convert hunting findings into:
    • Security incidents
    • New detection rules (SIEM / EDR / XDR)
    • Change or service requests (misconfigurations, logging gaps)
  • Collaborate with SOC, Incident Response, and Threat Intelligence teams
  • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated)

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026totaled $14.8billion.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunter
Threat Hunter

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
Senior Associate - Threat Hunting
Senior Associate - Threat Hunting

NPCI • Hyderabad

On-site
INR 900,000 - 1,300,000
Tower Lead (Support & Operations)
Tower Lead (Support & Operations)

HCL Technologies Limited • Pune District

On-site
INR 4,500,000 - 7,000,000
Threat Hunting Analyst
Threat Hunting Analyst

Network Intelligence India • Bengaluru

On-site
INR 800,000 - 1,500,000
Senior Associate - Threat Hunting
Senior Associate - Threat Hunting

NPCI International • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Comprehensive medical, accidental, and life insurance
On-site medical center and mental wellness support
Inclusive parental leave
+3
Threat hunting
Threat hunting

Tata Consultancy Services • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Senior Threat Hunter
Senior Threat Hunter

UST • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

Broadway Global Services • Bengaluru

On-site
INR 400,000 - 700,000
Challenging role
Certification support
Growth opportunities
+2
Senior Associate Threat Intelligence
Senior Associate Threat Intelligence

NPCI • Hyderabad

On-site
INR 900,000 - 1,500,000
Insurance & Wellness program
Relocation & Mobility benefits
Home loan support
Sr. Security Engineer
Sr. Security Engineer

Hitachi Automotive Systems Americas, Inc. • New Delhi

Hybrid
INR 8,563,000 - 12,369,000