HireHireZeta jobs › SIEM & SecOps Engineer II

SIEM & SecOps Engineer II

Apply for this role or explore on the map →

Responsibilities:: Design, develop, tune, and maintain SIEM detection use cases and correlation rules. Investigate and triage security alerts escalated from L1 analysts across multiple security platforms, including: Network Firewalls Web Application Firewalls (WAF) Cloud Platforms Endpoint Security (Linux/macOS) Other security monitoring solutions Perform threat investigations with a strong focus on Linux security mainly on MacOS devices , including threat hunting, log analysis, and detection engineering. Create, tune, and optimize dashboards, alerts, detection logic, parsers, and log collection pipelines. Build and maintain log ingestion workflows using tools such as Logstash, Fluentd, Fluent Bit , or similar ETL/data pipeline technologies. Support cloud-native SIEM operations based on AWS OpenSearch , including index management, parsing, dashboards, detection tuning, and platform optimization. Assist with incident response activities, investigations, containment, and root cause analysis under the guidance of the SOC Lead. Develop and maintain SOAR playbooks and automation workflows to improve SOC efficiency. Contribute to Detection-as-Code workflows using Git-based version control and CI/CD pipelines. Work closely with engineering teams to onboard new log sources, improve telemetry quality, and fine-tune data collection. Support and enhance AI-driven capabilities within the SIEM, including assisting in the development and integration of AI agents for SOC operations. Continuously research emerging threats, attack techniques, and detection methodologies to improve the SOC's detection coverage.

Skills:: Good understanding of SIEM query languages such as OpenSearch Query DSL , Sigma , or similar detection rule/query languages. If not already experienced, the candidate should demonstrate the ability to learn and become productive quickly. Comfortable working with open-source security tools and modern security engineering practices. Experience supporting SOAR automation and playbook development. Ability to investigate alerts across cloud, endpoint, network, and application security technologies. Strong analytical, troubleshooting, and communication skills with the ability to work independently while collaborating effectively within the SOC team. Enthusiastic, proactive, self-driven, and quick to learn new technologies. The candidate should be able to rapidly understand and adapt to the existing SOC environment, detection engineering workflows, tooling, and operational processes with minimal supervision. Familiarity with MITRE ATT&CK mapping. Experience in working with OpenSource SIEM platforms such as ELK/Wazuh/Bro review/suggest latest trends of SIEM to integrate to our in-house SIEM

Experience and Qualifications:: 3–6 years of experience in SOC, Detection Engineering, Threat Detection, or Incident Response. Strong fundamentals in Computer Networking and Operating Systems (Linux/Windows) . Strong hands-on experience investigating Linux security incidents and developing Linux-focused detection use cases. Experience working with cloud-native SIEM platforms , preferably AWS OpenSearch . Hands-on experience creating SIEM detection rules, dashboards, parsers, log normalization, and use case tuning. Experience with log collection and processing tools such as Logstash, Fluentd, Fluent Bit , or similar ETL solutions. Good understanding of Kubernetes , containers, and microservices-based environments from a security monitoring perspective. Experience working with Detection-as-Code methodologies using Git and CI/CD workflows. Proficiency in Python and strong scripting skills (Bash/PowerShell or similar).

More roles at Zeta

See Zeta & thousands more on the map

Every tech & IT company hiring across India — with AI match scores — on one live map.

Open the map →