Architects and optimizes SIEM and Cribl telemetry pipelines; onboards diverse security data sources; develops MITRE ATT&CK-aligned detections; tunes alerts; builds dashboards and hunting queries; monitors ingestion health, costs, and coverage; troubleshoots pipeline and detection failures; mentors engineers and analysts; and maintains technical documentation, runbooks, metrics, and governance standards.
Duties & Responsibilities
- Architect and optimize SIEM platforms (e.g., Microsoft Sentinel, Splunk), including ingestion pipelines, parsing/normalization, enrichment, and correlation logic.
- Engineer and operate Cribl Stream and Cribl Edge for log routing, filtering, transformation, enrichment, data reduction, and destination fanout (SIEM, data lake, cold storage).
- Design and maintain telemetry onboarding with schema mapping, collectors/agents, connectors, API integrations, replay, and edge collection for diverse sources (endpoint, network, cloud, identity, app).
- Develop advanced detections and analytics (rules, queries, correlations) aligned to MITRE ATT&CK, emerging TTPs, and threat intelligence; measure detection efficacy and coverage.
- Lead systematic alert tuning to reduce false positives and improve signaltonoise, leveraging Cribl pipelines and SIEM analytics to standardize high-fidelity events.
- Build investigation assets (dashboards, hunting queries, data models) that accelerate SOC workflows and rootcause analysis across telemetry domains.
- Monitor ingestion health and cost (EPS/GB/day, license utilization), implement Criblbased data controls (sampling, routing, suppression) to ensure reliability and budget adherence.
- Perform RCA on detection gaps and pipeline failures; implement durable fixes in Cribl routes/pipelines and SIEM parsing/enrichment layers.
- Mentor engineers and analysts on KQL/SPL, detection engineering patterns, Cribl pipeline design, and telemetry best practices; conduct peer reviews and standards governance.
- Maintain documentation: data dictionaries, detection catalogs, Cribl pipeline/runbooks, ingestion maps, and metrics reporting on coverage, fidelity, MTTR, and pipeline SLOs.
Requirements
Basic Qualifications
- Solid understanding of network protocols, data protection mechanisms, and threat landscapes
- Hands-on experience with security systems, including firewalls, intrusion detection systems, anti-virus software, etc.
Preferred Qualifications
- Industry-recognized certifications (e.g., CISSP, CISM, CEH)
- Master’s degree in Cybersecurity or a related field
Similar Jobs
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Owns the architecture, engineering standards, and technology roadmap for a secure healthcare data platform across AWS, Azure, and Databricks. Designs ingestion, lakehouse, interoperability, governance, privacy, analytics, and operational reporting solutions. Establishes standards for Spark, Python, SQL, data quality, observability, metadata, CI/CD, infrastructure as code, and disaster recovery. Leads healthcare data interoperability, security architecture, proofs of concept, performance assessments, technical roadmaps, and executive decision support.
Top Skills:
Amazon EventbridgeAmazon S3Apache IcebergSparkAthenaAuto LoaderAWSAws LambdaAws Secrets ManagerAws Step FunctionsAzureCi/CdClinical NlpCloudwatchCptDatabricksDatabricks SqlDatabricks WorkflowsDelta LakeEcsEksFhir R4Hl7 V2Icd-10Infrastructure As CodeJSONKmsLlmsLoincMlopsNdjsonOmop CdmPysparkPythonRxnormSnomed CtSnowflakeSQLSreTrinoUnity CatalogXML
Digital Media • Information Technology • News + Entertainment
Designs, develops, and optimizes scalable data pipelines and structures for analytics and downstream apps. Implements SQL transformations, ingestion frameworks, cloud data solutions (Snowflake, Databricks), ensures data quality, lineage, and governance, and mentors junior engineers while improving internal tools and automation.
Top Skills:
AirflowSparkAWSAws S3AzureCi/CdDatabricksDbtGCPIcebergPythonSnowflakeSQL
Digital Media • Information Technology • News + Entertainment
Implements, refines, validates, trains, and deploys machine learning models for company products. Designs and monitors data pipelines, evaluates internal and external ML solutions, documents technical requirements, and develops proof-of-concept strategies. Conducts case studies, contributes to research, patents, APIs, and intellectual property, and provides recommendations to support future product development. Requires independent judgment and availability for variable schedules, including nights and weekends.
Top Skills:
APIsData PipelinesMachine Learning
What you need to know about the Chennai Tech Scene
To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.


