Job Description

Job Description – SIEM Lead Engineer Role Overview

The SIEM Lead Engineer is responsible for leading the design, development, and optimization of SIEM alerting, enrichment, and monitoring capabilities using Splunk. This role focuses on improving alert fidelity, contextual enrichment, detection engineering, and overall SOC effectiveness. The role acts as a technical lead and escalation point, working closely with SOC Analysts, Threat Detection, Security Engineering, and platform teams.

Key Responsibilities

  • Lead engineering and optimization of Splunk-based SIEM alerting and monitoring.
  • Design, develop, and tune correlation rules and detections to reduce false positives.
  • Own alert lifecycle management including creation, tuning, validation, and retirement.
  • Design and implement alert enrichment using IAM, CMDB, vulnerability, and threat intelligence sources.
  • Ensure alerts are enriched with user, asset, privilege, and business context.
  • Engineer and maintain Splunk data ingestion, normalization, and CIM compliance.
  • Support onboarding of log sources across endpoint, network, cloud, and identity platforms.
  • Develop detection use cases mapped to MITRE ATT&CK.
  • Act as L3 escalation for complex SIEM and detection issues.
  • Maintain SOPs, runbooks, and SIEM documentation.
  • Mentor SIEM engineers and provide technical guidance.


Required Skills & Experience

  • 6–10 years of experience in SIEM or security engineering roles.
  • Strong hands-on expertise with Splunk Enterprise / Splunk ES.
  • Proven experience in SIEM alert development, tuning, and enrichment.
  • Strong understanding of security telemetry across endpoint, network, cloud, and IAM.
  • Proficiency in SPL (Search Processing Language).
  • Experience with MITRE ATT&CK and SOC workflows.
  • Experience integrating SIEM with IAM, CMDB, vulnerability, and threat intel platforms.


Preferred Qualifications

  • Experience in regulated environments such as healthcare or financial services.
  • Exposure to SOAR platforms and automated response workflows.
  • Scripting experience using Python or PowerShell.
  • Relevant security or Splunk certifications.


Job Details

Role Level: Not Applicable Work Type: Full-Time
Country: India City: Hyderabad ,Telangana
Company Website: https://www.providence.in/ Job Function: Cybersecurity
Company Industry/
Sector:
Hospitals and Health Care

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


Recent Jobs
View More Jobs
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn