Jump to content

Technical & Bus Analyst - Data & Applications - Stone Mountain, GA | TCS Job


 Share

Job Opportunity Details

Type

Full Time

Salary

Not Telling

Work from home

No

Weekly Working Hours

Not Telling

Positions

Not Telling

Working Location

Stone Mountain, GA, Stone Mountain, GA, United States   [ View map ]
Must Have Technical/Functional Skills
 Technical Expertise 
•5+ years working with SIEM platforms (Splunk preferred). 
•Advanced experience with CIM, ECS, or equivalent log normalization schemas. 
•Strong understanding of: 
oJSON logging 
oSyslog/NXLog 
oCloud logging architectures (AWS/GCP/Azure) 
oApplication security telemetry 
oOSQuery / EDR / DNS / WAF logs 
•Proven ability to write: 
oSource type definitions 
oField extraction rules 
oCorrelation logic 
oDetection playbooks 
 
Cybersecurity Knowledge & Competency 
•Familiarity with MITRE ATT&CK, SIGMA rules, NIST 800-53 frameworks. 
•Experience supporting SOC, IR, SIEM, Detection Engineering, or Threat Ops teams. 
•Understanding modern attack techniques, identity abuse patterns, and cloud threats. 
 
Roles & Responsibilities
•Engage and coordinate with Application Owners, Product Teams, DevOps, and Engineering. 
•Validate log types, formats, schemas, and logging methods (syslog, API, CloudTrail, JSON, custom formats). 
•Define onboarding requirements including event types, fields, timestamps, user identity, error codes, 
•and security-critical attributes. 
•Evaluate logs for completeness, reliability, and compliance with industry standard schemas. 
•Map log sources to Splunk’s Common Information Model (CIM) or equivalent normalization frameworks. 
•Log parsing, field extraction, enrichment, and timestamp normalization. 
•Development of CIM-compliant extractions for all new log sources. 
•Documentation of field dictionaries, mappings, and SIEM source type definitions. 
•Validation of proper taxonomy alignment across categories such as: 
oAuthentication 
oAuthorization 
oApplication activity 
oNetwork activity 
oSecurity events 
oError/failure conditions 
oAdministrative and privileged actions 
•Mapping application behaviors to relevant attack techniques (MITRE ATT&CK). 
•Identifying and documenting detection opportunities. 
•Authoring and implementing: 
oCorrelation searches 
oBehavioral detections 
oAnomaly models 
oHigh-fidelity alert logic 
•Ensuring each detection has: 
oDefined data dependencies 
oOperational owner 
oSeverity/priority rating 
oTriage response play 
•Operationalizing detections into Security Operations Runbooks, including: 
oPreconditions 
•Indicators & patterns 
oTriage steps 
oContainment actions 
oEscalation paths 
oEvidence checklist 
 
Salary Range: $64,000 - $125000 a year
#LI-CM2


More Information

Application Details

  • Organization Details
    TCS / Tata Consultancy Services
 Share


User Feedback

Recommended Comments

There are no comments to display.

Join the conversation

You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Add a comment...

×  Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×  Your link has been automatically embedded.   Display as a link instead

×  Your previous content has been restored.   Clear editor

×  You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...