Source description
About the role
Senior SIEM Engineer - J50694 Role & responsibilities Job Location: Airoli, Navi Mumbai (Client Location) 5 days Work from Office - General Shift About the Role We are looking for an experienced and driven SIEM Engineer to join our growing SOC Services team. The candidate will be responsible for onboarding new log sources, ensuring data normalization, maintaining log quality, and supporting detection engineering initiatives. The candidate should have strong hands-on experience in SIEM platform configuration, log parsing, data validation, and security use-case enablement (preferably on the Securonix platform). Key Responsibilities 1. Onboard and integrate multiple security and IT data sources into the SIEM platform. 2. Support onboarding of Network security devices (Firewalls, IDS/IPS, WAF, Proxies), EDR/XDR, IAM, Cloud platforms (AWS, Azure, GCP), Database, and Infrastructure logs. 3. Configure log collection using agents, APIs, syslog, connectors, and cloud-native integrations. 4. Validate log ingestion, field extraction, parsing, and normalization. 5. Ensure logs align with the SIEM data model and taxonomy standards. 6. Perform data quality checks, including completeness, timeliness, and accuracy. 7. Design and implement log parsing rules, regex extraction, and field mappings. 8. Ability to develop custom parsers and connectors. 9. Troubleshoot ingestion and parsing issues across diverse data formats. 10. Work closely with SOC analysts, detection engineers, platform administrators, and customers. 11. Provide onboarding guidance and log requirement recommendations. 12. Support audit and compliance log validation activities. Required technical skills sets 13. Hands-on experience with at least one SIEM platform. 14. Experience onboarding logs from AWS CloudTrail, GuardDuty, VPC Flow Logs, Azure Monitor, Entra ID logs, SaaS applications via APIs. 15. Strong understanding of: Syslog protocols REST APIs, JSON, XML, CSV log formats, Regex and log parsing techniques, Event normalization and enrichment. 16. Working knowledge of Python / Shell scripting. 17. Experience with Linux/Unix and Windows logging mechanisms. 18. Knowledge of network protocols and security telemetry. 19. Understanding of SOC operations and incident detection lifecycle and MITRE framework. Required Experience 20. 5-6 years of hands-on experience in managing an enterprise SIEM platform. 21. Strong architectural knowledge of SIEM 22. Proven track record in SIEM platform management and onboarding new data sources and integration
More at Sampoorna Consultants
Related open roles
Senior SOC Content Engineer
Mumbai
Senior SOAR Engineer
Mumbai
Cyber AI Security Architect-Manager(Diversity)-BLR/GGN/Noida (Bengaluru)
Bangalore
Cyber AI Security Architect/Manager
Bangalore
Information Technology Security Engineer
Bangalore
Cyber AI Security Architect-Manager(Diversity)-BLR/GGN/Noida
Bangalore