Must Have Technical/Functional Skills
Technical Expertise
•5+ years working with SIEM platforms (Splunk preferred).
•Advanced experience with CIM, ECS, or equivalent log normalization schemas.
•Strong understanding of:
oJSON logging
oSyslog/NXLog
oCloud logging architectures (AWS/GCP/Azure)
oApplication security telemetry
oOSQuery / EDR / DNS / WAF logs
•Proven ability to write:
oSource type definitions
oField extraction rules
oCorrelation logic
oDetection playbooks
Cybersecurity Knowledge & Competency
•Familiarity with MITRE ATT&CK, SIGMA rules, NIST 800-53 frameworks.
•Experience supporting SOC, IR, SIEM, Detection Engineering, or Threat Ops teams.
•Understanding modern attack techniques, identity abuse patterns, and cloud threats.
Roles & Responsibilities
•Engage and coordinate with Application Owners, Product Teams, DevOps, and Engineering.
•Validate log types, formats, schemas, and logging methods (syslog, API, CloudTrail, JSON, custom formats).
•Define onboarding requirements including event types, fields, timestamps, user identity, error codes,
•and security-critical attributes.
•Evaluate logs for completeness, reliability, and compliance with industry standard schemas.
•Map log sources to Splunk’s Common Information Model (CIM) or equivalent normalization frameworks.
•Log parsing, field extraction, enrichment, and timestamp normalization.
•Development of CIM-compliant extractions for all new log sources.
•Documentation of field dictionaries, mappings, and SIEM source type definitions.
•Validation of proper taxonomy alignment across categories such as:
oAuthentication
oAuthorization
oApplication activity
oNetwork activity
oSecurity events
oError/failure conditions
oAdministrative and privileged actions
•Mapping application behaviors to relevant attack techniques (MITRE ATT&CK).
•Identifying and documenting detection opportunities.
•Authoring and implementing:
oCorrelation searches
oBehavioral detections
oAnomaly models
oHigh-fidelity alert logic
•Ensuring each detection has:
oDefined data dependencies
oOperational owner
oSeverity/priority rating
oTriage response play
•Operationalizing detections into Security Operations Runbooks, including:
oPreconditions
•Indicators & patterns
oTriage steps
oContainment actions
oEscalation paths
oEvidence checklist
Salary Range: $64,000 - $125000 a year
#LI-CM2
More Information
Application Details
- Organization DetailsTCS / Tata Consultancy Services


Recommended Comments
There are no comments to display.
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.