Senior SOC Content Engineer - "SIEM", "Security Information, Event Management" - Mumbai, 5.00 - 8.00 yrs | Sampoorna (J50693)

job opening

Job Summary


Experience:

5.00 - 8.00  Years 

Industrial Type:

IT-Hardware & Networking

Location:

Mumbai

Functional Area:

IT Software - Client Server

Designation:

Senior SOC Content Engineer

Key Skills:

"SIEM" OR "Security Information and Event Management"

Educational Level:

Graduate/Bachelors

Job Post Date:

Stream of Study:

Degree:

BCA, BE-Comp/IT, BE-Other, BSc-Comp/IT, BSc-Other, BTech-Comp/IT, BTech-Other, MCA, ME-Comp/IT, ME-Other, MSc-Comp/IT, MSc-Other, MTech-Comp/IT, MTech-Other

Company Description


Our Client is built on an AI-first, technology-agnostic approach to cybersecurity - engineered to outpace evolving threats, maximize ROI from existing investments, and strengthen enterprise-wide secu rity posture. Our Client help organizations tackle complex cybersecurity challenges with intelligence-led, outcome-focused services - delivered by experts with deep real-world experience to drive tangible business outcomes.

Job Description


Job Location: Airoli, Navi Mumbai (Client Location)
5 days Work from Office - General Shift

About the Role:
We are looking for an experienced and driven SOC Content Engineer to join our growing SOC Services team. The candidate will be responsible for tuning correlation rules, reducing false positives, managing content lifecycle, and aligning detection use cases with evolving threat landscapes. The ideal candidate should have hands-on experience in SIEM rule engineering, detection tuning, analytics validation, and SOC operational alignment (preferably on the Securonix platform).

Key Responsibilities
1. Design and develop new detection use cases aligned with the MITRE ATT&CK
framework, threat intelligence inputs, Risk scenarios, and business impact
2. MITRE ATT&CK coverage improvement.
3. Build use cases- Policy-based, correlation-based, behavior-based, risk-scoring-based.
4. Translate threat models/ scenarios into meaningful use cases.
5. Build detection logic based on- UEBA, Insider threat, Lateral movement, Data exfiltration.
6. Define policy baselines and deviation thresholds.
7. Continuously enhance detection models/ policies based on real SOC feedback.
8. Provide policy recommendations to reduce alert fatigue/ reduce false positives.
9. Provide validation/ testing of policies with synthetic data and validate detection and alert quality.
10. Quarterly policy review and validations aligned to the MITRE framework.
11. Work with the onboarding team to ensure the missing logs are ingested to enhance the use case/ detection logics.
12. Support with compliance and audit-related activities.
13. Document and maintain all stages of the policy /content management cycle for compliance purposes.

Required technical skill sets
14. Hands-on experience with at least one SIEM platform.
15. Experience in Correlation rule creation, behavioral analytics tuning, Query languages (SPL, KQL, AQL, SQL-like queries), and understanding of log normalization and data taxonomy.
16. Strong analytical mindset with threat modeling capability.
17. Experience generating synthetic logs and test scenarios.
18. Ability to analyze JSON/XML structured logs.
19. Ability to convert business risks into technical detection logic.

Required Experience
20. 5-6 years of hands-on experience in SIEM content creation and management.
21. Strong threat analysis knowledge

announce
Did not find a matching job? You can still send your CV to jobs@sampoorna.com or Register Here