TymblHub

© 2026 TymblHub

Senior SIEM Engineer (L3)

Tata Consultancy Services
Posted on
Tata Consultancy Services logo

Experience
5 - 10 yrs
Salary (CTC)
₹10.6L - ₹15.4L
Job Location
Bengaluru, India
Vacancy
1
Designation
Siem Engineer
Job Type
Not specified

Job Description

Walk-In (Inperson interview)-TCS Yeshwanthpur Towers

Yeshwanthpur Industrial Suburb, Yeswanthpur, Bangalore


Date- 08 Aug-26 (Saturday)


Location -Banglore


Job Description: Senior SIEM Engineer (L3)

Position Overview

The Senior SIEM Engineer (L3) is responsible for architecting, optimizing, and leading the endtoend Security Information and Event Management (SIEM) environment. This role demands deep technical expertise, advanced use-case development, automation capability, and strong experience supporting highseverity security incidents. The L3 SIEM Engineer acts as the highest escalation point for SIEM-related issues and works closely with SOC, Threat Hunting, DFIR, Cloud, and Infrastructure teams to ensure strong detection coverage and operational resilience.

Key Responsibilities

1. SIEM Architecture & Platform Ownership

  • Lead the design, implementation, and optimization of enterprise SIEM (Sentinel / Splunk / QRadar / ArcSight / LogRhythm).
  • Drive roadmap planning, capacity management, data onboarding strategy, and platform scaling.
  • Own SIEM health, reliability, redundancy, and performance monitoring.

2. Advanced Log Onboarding & Data Engineering

  • Define logging standards and ensure complete visibility across endpoints, servers, cloud, applications, and security tools.
  • Build custom parsers, log collectors, ingestion pipelines, and normalization schemas.
  • Work with application and network teams to integrate complex data sources (API logging, custom app logs, firewall advanced logging, etc.).

3. Detection Engineering & UseCase Development

  • Build complex analytics rules, correlation searches, machinelearningbased detections, and anomaly models.
  • Lead continuous rule tuning to reduce false positives and improve detection fidelity.
  • Map detections to MITRE ATT&CK, NIST, and organizational threat models.

4. Incident Response & Threat Hunting Support

  • Serve as L3 escalation point for SOC and DFIR teams during highseverity incidents.
  • Perform advanced event correlation, pivoting, timeline reconstruction, and deep-dive threat investigations.
  • Conduct proactive threat hunting using SIEM datasets and behavioral analytics.

5. SOAR Automation & Integration

  • Develop advanced SOAR playbooks for automated enrichment, response, ticketing, and containment actions.
  • Integrate SIEM with EDR, IAM, CASB, vulnerability scanners, firewalls, cloud-native controls, and ticketing systems.
  • Lead automation strategy to reduce manual analyst workload.

6. Compliance, Reporting & Governance

  • Build executive dashboards, SLA compliance reports, and operational monitoring panels.
  • Ensure adherence to ISO 27001, NIST, PCI-DSS, SOC2, and internal audit requirements.
  • Own log retention, access control, and monitoring governance.

7. Knowledge Management & Mentoring

  • Prepare and maintain runbooks, SOPs, parser guides, and onboarding checklists.
  • Provide mentorship and guidance to L1/L2 SOC analysts and junior engineers.
  • Conduct SIEM training sessions, purpleteam exercises, and usecase validation workshops.

Required Skills & Experience

  • 510+ years of overall cybersecurity experience, with minimum 35 years in SIEM engineering.
  • Deep handson experience with one or more major SIEM platforms.
  • Strong understanding of: 
  • KQL, SPL, AQL, EQL or equivalent SIEM query languages
  • Log parsing, data transformation, and enrichment techniques
  • Windows, Linux, network protocols, AD, IAM, cloud logging
  • Threat detection frameworks (MITRE ATT&CK, Cyber Kill Chain, NIST)
  • Incident response processes and threat investigation

Preferred Skills

  • Expertise with SOAR platforms (Sentinel, Splunk SOAR, Palo Alto XSOAR, Swimlane).
  • Experience building custom connectors, scripts, or automations (Python, PowerShell, API integration).
  • Cloud security logging experience (Azure, AWS, GCP).
  • Certifications such as: 
  • SC200 / AZ500
  • Splunk Architect / Power User
  • IBM QRadar Certified Specialist
  • GCIA / GMON / GCIH / CEH

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.