Job Description
Sr Cyber Security Engineer (SIEM Engineer)
Job Description**
About Gurucul:
Gurucul is a global cyber security company that delivers a unified, cloud-native Security
Analytics and Operations Platform that includes Next-Gen SIEM, Open XDR, UEBA, and
Identity Analytics. Our mission is to help organizations protect their most valuable assets by detecting, predicting, and preventing threats through machine learning behavior profiling, real-
time analytics, and open data security frameworks. We serve Global 1000 enterprises and government agencies around the world.
JOB DESCRIPTION
Gurucul is seeking a motivated SIEM Implementation Engineer (3–5 years of experience)
to join our Professional Services team. The ideal candidate is passionate about security
analytics, hands-on engineering, and delivering exceptional customer experiences. You will
work directly with enterprise customers to implement, configure, and operationalize our
industry-leading SIEM solution. The role combines technical delivery, problem-solving,
customer interaction, and continuous improvement of SIEM capabilities.
This position requires strong fundamentals in SIEM technologies, log source integration,
detection engineering, and system troubleshooting across Linux/Windows environments.
Travel may be required for onsite engagements.
RESPONSIBILITIES
Implementation & Deployment
• Install, configure, and deploy Gurucul's Next-Gen SIEM platform in customer
environments (on-prem, cloud, hybrid).
• Integrate diverse log sources, ensuring proper parsing, normalization, and data
quality.
• Configure data ingestion pipelines, connectors, agents, collectors, and parsing rules.
Customer Engagement & Delivery
• Communicate technical concepts clearly to customers during workshops, onboarding
calls, and deployment sessions.
• Assist customers in defining integration requirements, architectural considerations,
and best practices.
• Create implementation documentation, deployment guides, and runbooks.
SIEM Engineering & Optimization
• Customize and tune SIEM rules, dashboards, correlation logic, and behavioural
models as per customer requirements.
• Perform data integrity checks and troubleshoot ingestion issues, missing fields, and
parsing failures.
• Optimize platform performance, resource utilization, and ingestion throughput.
Use-Case & Detection Enablement
• Assist customers in implementing new use cases mapped to MITRE ATT&CK and
industry threats.
• Build and refine dashboards, queries, correlation rules, and alerting logic.
• Support UEBA model validation and help reduce false positives by tuning logic and
baselines.
Troubleshooting & Technical Expertise
• Troubleshoot SIEM platform issues on both Windows and Linux environments.
• Work with databases (MSSQL, MySQL) to validate ingestion, queries, and backend
configurations.
• Collaborate with product and engineering teams for escalations or platform-related
issues.
Training & Knowledge Transfer
• Conduct customer training sessions on SIEM features, log integrations, dashboards,
reporting, and detection frameworks.
• Provide continuous guidance, best practices, and operational recommendations to
customers.
Operational Deliverables
• Maintain up-to-date documentation including architecture diagrams, SOPs, and
integration playbooks.
• Support pre-sales during POCs, demos, and technical deep dives when required.
• Ensure customer satisfaction through timely delivery, clear communication, and
proactive engagement.
EXPERIENCE
Candidates should have experience in the following:
• 3–5 years of hands-on experience implementing and supporting SIEM solutions
(Gurucul, Splunk, QRadar, ArcSight, Sentinel, or similar).
• Experience integrating common log sources: Windows, Linux, firewalls, proxy, identity
systems (AD/LDAP, Okta), EDR, Cloud (AWS/Azure/GCP).
• Strong understanding of log parsing, normalization, data pipelines, and data quality
validation.
• Experience writing correlation rules, SQL queries, dashboards, and SIEM alert logic.
• Basic scripting in Python, PowerShell, or Shell for automation and troubleshooting.
• Understanding of MITRE ATT&CK Framework and common attack techniques.
• Familiarity with networking concepts, cyber security domains, and threat detection
fundamentals.
• Experience working directly with enterprise customers in implementation or support
roles.
• Good communication and documentation skills.
Preferred Skills (Good to Have)
• Exposure to Big Data components (Kafka, Elasticsearch, Hadoop).
• Knowledge of Identity Analytics, UEBA, or behavior analytics models.
• Experience with REST APIs, integration scripts, or automation frameworks.
EDUCATION
• Bachelor's degree in computer science, Engineering, Information Security, or
equivalent experience.
• Security certifications such as Security+, CEH, GCIA, or vendor-specific SIEM
certifications are a plus.
LOCATION / TRAVEL
Position is based in Pune, India. This role may require up to 20–30% travel for customer
onsite implementation activities.
To apply:
Please send resumes to [Confidential Information] for consideration
More Info
Key Skills
data pipelines
SIEM alert logic
MITRE ATT CK Framework
AD
log parsing
correlation rules
Gurucul
Windows
Shell
