Title: Senior SIEM & SOAR Expert – Splunk Cloud
Location: Noida/Bangalore/Remote
Duration: Contract
We are seeking a highly experienced SIEM & SOAR expert to lead our transition from Devo to Splunk Cloud and own the end to end SIEM lifecycle. This role requires deep expertise in Splunk infrastructure, data onboarding, parsing, noise reduction, and use case engineering, with a strong focus on security outcomes, scalability, and operational efficiency.
Key Responsibilities
Splunk Architecture & Operations
- Design, implement, and manage Splunk Cloud architecture, ensuring scalability, performance, and high availability
- Own Splunk infra components including data pipelines, index management, retention, and cost optimization
- Act as the technical authority for Splunk platform governance and best practices
Data Ingestion & Normalization
- Lead onboarding of diverse log sources (security, infra, cloud, SaaS, endpoints, IAM, network)
- Build and optimize parsing, field extractions, CIM compliance, and data normalization
- Ensure high data quality, reliability, and consistency across sources
Noise Reduction & Signal Optimization
- Drive alert noise compression, deduplication, and tuning strategies
- Optimize correlation logic to improve signal to noise ratio and SOC efficiency
- Continuously refine detections based on threat trends and operational feedback
Use Case & Detection Engineering
- Design and implement high fidelity security use cases mapped to MITRE ATT&CK
- Build advanced correlation searches, dashboards, reports, and KPIs
- Partner with SOC and IR teams to operationalize detections and response workflows
SOAR Integration & Automation
- Integrate Splunk with SOAR platforms to enable automated triage and response
- Design playbooks for common security incidents to reduce MTTR
- Collaborate with security, infra, and app teams to drive automation adoption
Migration & Stakeholder Leadership
- Lead SIEM migration strategy from Devo to Splunk Cloud
- Provide technical leadership, documentation, and mentoring
- Engage with stakeholders, vendors, and leadership to align SIEM strategy with business risk
Required Experience & Skills
- 10+ years of hands on experience in SIEM engineering and operations
- Deep expertise in Splunk Cloud (architecture, administration, tuning, and optimization)
- Strong experience with data ingestion, parsing, field extraction, and CIM
- Proven ability in noise reduction, alert tuning, and use case engineering
- Hands on experience with SOAR tools and security automation
- Strong understanding of security operations, threat detection, and incident response
- Experience working in large scale enterprise environments
Education
- Bachelor’s degree (B.Tech / B.E) in Computer Science, Information Technology, Cybersecurity, or a related field