TM
Google SecOps / SIEM Engineer _ Infosys
Tailored Management
๐ฎ๐ณ India
On-site
1 month ago
- SIEM
- Splunk
- Threat Intelligence
- Threat Modeling
- Live Activities
- Microsoft Sentinel
- Python
- PowerShell
- AWS
- Azure
- GCP
1 month ago
Role: Google SecOps / SIEM Engineer
Experience: 5+ Years
Location: Pan India
Domain: Cyber Security / SIEM / SOC
Primary Skill: Google SecOps (Chronicle SIEM)
Vendor Rate:โน8,330 โ โน9,330
Detailed Job Description:
Key Responsibilities
- Experience migrating from an incumbentSIEM/SOAR platform to Google SecOps is preferred.
- Familiarity with mappingRadar rules, Building Blocks (BBs), and Reference Sets (RS) to Google SecOps equivalents.
- MigrateNetwork Flow Data (NetFlow, sFlow, J-Flow) to the Google SecOps equivalent.
- Conductrequirements gathering and security use-case assessments.
- Configure and validatelog source onboarding into Google SecOps.
- PerformUDM normalization and data validation activities.
- Develop and customizeparsers for new log source integrations.
- Migrate SIEM content fromSplunk, QRadar, ArcSight, Sentinel, etc., to Google SecOps.
- Map existinguse cases/rules to Google SecOps detections.
- Performgap analysis and monitoring coverage assessments.
- Design, develop, and optimizedetection rules and correlation logic.
- Create security use cases aligned toMITRE Telecommunication&CK and Cyber Kill Chain frameworks.
- Review and tune SIEM content to improvedetection effectiveness and reduce false positives.
- Integrate security tools, cloud platforms, and third-party solutions withGoogle SecOps.
- Builddashboards, reports, KPIs, and operational metrics.
- Conductthreat hunting using Google SecOps and threat intelligence.
- Performthreat modeling and identify monitoring opportunities.
- Recommend improvements toSOC processes, detection coverage, and platform utilization.
- DevelopSOPs, runbooks, playbooks, and engineering documentation.
- SupportKT, reverse KT, shadowing, and go-live activities.
- Drivesecurity monitoring modernization and automation initiatives.
Mandatory Skills:
- 5+ years of Information Security and SIEM Engineering experience.
- Strong hands-on experience withGoogle SecOps (Chronicle SIEM).
- Experience withSplunk, IBM QRadar, ArcSight, Microsoft Sentinel, or similar SIEM platforms.
- Expertise inSIEM onboarding, content engineering, and platform transformation.
- Experience withparser development and log source integrations.
- Strong knowledge ofDetection Engineering and Threat Hunting.
- Knowledge ofMITRE Telecommunication&CK, Cyber Kill Chain, and Threat Intelligence.
- Scripting knowledge (Python/PowerShell) preferred.
- Experience working withcloud security environments (AWS/Azure/GCP) preferred.
Google SecOps / SIEM Engineer _ Infosys ยท Tailored Management