Search by job, company or skills

  • Posted 3 hours ago
  • Be among the first 10 applicants

Job Description

Greetings from TCS!!

ROLE-SOC-SIEM Google Secops

Experience-7-10 yrs

Location-Hyderabad

Job Description: Google Chronicle SIEM Engineer , SOC Automation Specialist & Platform management

We are seeking a highly skilled Google Chronicle SIEM Engineer with expertise in SOC automation to enhance our detection capabilities and reduce false positives across the security landscape. The ideal candidate will be responsible for designing, developing, and maintaining advanced detection use cases, automation workflows, and integrations to strengthen our overall security posture and improve operational efficiency within the SOC environment.

Tools:

  1. Google Chronical SIEM
  2. Bind plane
  3. Cribl

Key Responsibilities

  • Design, implement, and optimize Google Chronicle SIEM for scalable log ingestion, parsing, normalization, and enrichment.
  • Create and updating correlation rules and use cases
  • Develop and fine-tune detection rules, parsers, and correlation logic to improve threat detection accuracy.
  • Integrate diverse log sources including firewalls, endpoint security, cloud services, IAM, ,network devices and etc.,.
  • Build and maintain custom parsers and dashboards to enhance visibility into security events.
  • Collaborate with threat hunting and detection engineering teams to identify and implement new detection logic.
  • Design and implement automation workflows (SOAR-based or API-based) to reduce analyst workload and response time.
  • Automate alert triage, enrichment, and response actions using scripts, playbooks, or orchestration tools.
  • Integrate Google Chronicle with automation platforms (e.g., Cortex XSOAR, Splunk SOAR, Swimlane, or custom Python-based frameworks).

Bindplane :

  • Deploy, configure, and manage Bind Plane agents across servers and cloud workloads.
  • Set up data ingestion from multiple sources (Windows, Linux, databases, firewalls, cloud services).
  • Normalize data schemas and forward logs to SIEM or observability tools (Chronicle, Elastic, Splunk).
  • Configure pipelines for log transformation, labeling, and enrichment.
  • Implement monitoring and alerts for agent health, performance, and log ingestion failures.
  • Optimize ingestion pipelines to reduce latency and improve reliability.

Cribl:

  • • Design, configure, and manage Cribl Stream pipelines for log, metric, and trace ingestion.
  • Build data routing rules to send telemetry to multiple destinations (SIEM, S3, Data Lake).
  • Implement data filtering, sampling, and transformation to optimize SIEM licensing.
  • Integrate enterprise log sources including servers, firewalls, cloud platforms, and APM tools
  • Manage Cribl workers, leaders, and edge deployments.
  • Troubleshoot ingestion delays, failed pipelines, and data parsing issues.
  • Work with security teams to onboard new data sources into SIEM through Cribl.
  • Develop proactive automation to reduce false positives, enhance correlation efficiency, and minimize noise.
  • Continuously refine detection rules using data analytics and threat intelligence to eliminate redundant alerts.
  • Conduct root cause analysis of recurring false positives and implement preventive detection improvements.
  • Collaborate with threat intel teams to update use cases with the latest IOCs, TTPs, and MITRE ATT&CK mappings.
  • Conduct periodic reviews and audits of alert quality, accuracy, and SOC performance metrics.
  • Develop and maintain detection engineering and automation frameworks with strong documentation.
  • Partner with SOC operations, engineering, and threat hunting teams for continuous improvement initiatives.
  • Participate in the design of proactive monitoring, AI/ML-based anomaly detection, and predictive automation models.
  • Drive initiatives for SOC modernization, focusing on agility, scalability, and advanced analytics.

Required Skills and Experience

  • 7–10 years of experience in Security Operations, SIEM Engineering, or SOC Automation.
  • Strong hands-on experience with Google Chronicle SIEM (log pipelines, UDM, rule writing, dashboards).
  • Proficiency in Python, API integrations, and automation frameworks (SOAR tools or custom automation scripts).
  • Solid understanding of SOC processes, incident response workflows, and playbook design.
  • Knowledge of MITRE ATT&CK, threat intelligence feeds, and behavior-based detection models.
  • Experience in reducing false positives, tuning detections, and implementing advanced correlation logic.
  • Familiarity with cloud security logging (GCP, AWS, Azure) and endpoint security integrations.

More Info

Job Type:
Industry:
Employment Type:

Job ID: 151743029