This page was automatically translated and may contain errors. View in English.
एचसीएलटेक

SOC Engineer

HCLTech

Bengaluru, Karnataka, India · पूरा समय

अप्लाय करने वाले प्रथम बनिए

अनुभव
3+ वर्ष
वेतन
INR 2,000,000 – INR 3,500,000 / year
उद्घाटन
1
की तैनाती
6 पहले
कार्य मोड
कार्यालय में हूँ
शिक्षा
कोई भी स्नातक
पात्रता
Candidates with any graduate degree are eligible to apply.
फिर शुरू करना
आवेदन करना आवश्यक है

आप कहाँ काम करेंगे

नौकरी का विवरण

Role Overview

As a SOC Detection and Automation Engineer at HCL Software in Bengaluru, you will play a pivotal role in enhancing the organization's security posture by crafting, implementing, and maintaining detection rules within our SIEM platform. Your efforts will focus on leveraging automation and AI features of the SIEM to optimize and expedite level 1 incident triage and response processes, improving the efficacy of the Security Operations Center.

Key Responsibilities

  • Develop, test, and deploy precise detection rules, correlation logic, and behavioral analytics within SIEM solutions.
  • Convert threat intelligence, known vulnerabilities, and attack frameworks like MITRE ATT&CK into actionable detection content.
  • Regularly tune existing detection mechanisms to reduce false alarms and enhance threat coverage.
  • Map detection content to security controls and incident response playbooks effectively.
  • Create and maintain automated playbooks for repetitive incident triage and initial response using the SIEM automation engine.
  • Integrate the SIEM with various security tools and enterprise systems through APIs to enable streamlined data exchange and automated reactions.
  • Apply AI and machine learning functionalities within SIEM for better alert ranking, anomaly spotting, and incident grouping.
  • Serve as a SIEM subject matter expert to manage data ingestion, logging policies, and platform health.
  • Collaborate with architecture and IT teams to onboard new data sources, ensuring correct normalization and parsing for detection.
  • Monitor operational stability of the SIEM environment and resolve related issues.
  • Partner with SOC analysts, threat hunters, and incident responders to tailor content supporting their workflows.
  • Engage in post-incident analyses to identify gaps and propose system improvements.
  • Keep abreast of emerging cybersecurity threats, attack methods, and tool updates.

Required Qualifications

  • Minimum 3 years of experience in Security Operations, Threat Hunting, or Detection Engineering.
  • Proven skill in designing and deploying detection capabilities on SIEM/SOAR platforms; experience with Palo Alto Networks XSIAM and Cortex XSOAR strongly preferred.
  • Strong knowledge of the cyber kill chain and MITRE ATT&CK framework.
  • Proficiency in Python and PowerShell scripting for automation and data tasks.
  • Extensive understanding of security logs, network protocols, operating systems (Windows, Linux), and cloud environments.
  • Experience integrating APIs and developing SOAR automation playbooks.
  • Strong analytical thinking, problem-solving acumen, and communication skills.

Preferred Qualifications

  • Hands-on experience working with Palo Alto Networks XSIAM platform for content and automation development.
  • Certifications such as PCNSE, PCSAE, GCIH, GCFA, or CISSP.
  • Familiarity with cloud security monitoring across AWS, Azure, or GCP.
  • Knowledge of threat intelligence platforms and feed integration into detection logic.

Eligibility

Applicants should hold at least a graduate degree to be considered for this position.

यदि आपको उत्तर चाहिए तो इसे छोड़ दें — हम इसका उपयोग किसी और चीज के लिए नहीं करेंगे।

ब्राउज़ करने के लिए क्लिक करेंड्रैग एंड ड्रॉप करें, या चिपकाएं एक स्क्रीनशॉट

PNG, JPG, GIF, MP4, WebM, MOV · प्रत्येक फ़ाइल का अधिकतम आकार 20MB · अधिकतम 5 फ़ाइलें

🤖
ऑनलाइन · तत्काल एआई सहायता