Posted on: 16/06/2026
Senior Security Telemetry Architect
NP : Very immediate joiners
Work Location : Hyderabad
Key Responsibilities :
Telemetry Platform Architecture :
- Design and own the Splunk architecture: distributed/clustered indexer and search head topology, SmartStore data tiering, forwarder management, and capacity planning for CTS-scale ingest.
- Define and govern log source onboarding standards, parsing/transforms, and Common Information Model (CIM) compliance across all data inputs.
- Architect and implement integration with Amazon Security Lake (AWS Security Lake): Open Cybersecurity Schema Framework (OCSF) normalization, AWS Lake Formation permissions, and Athena/Glue query connectivity to Splunk.
- Evaluate and maintain knowledge of complementary telemetry platforms including Microsoft Sentinel, CrowdStrike Falcon LogScale, Google Chronicle/SecOps, and IBM QRadar; provide platform comparison analysis and integration recommendations as the security stack evolves.
- Lead Kubernetes-native log collection design using Splunk Connect for Kubernetes (SCK), Fluentd, or Fluent Bit for CTS container environments.
- Produce architecture decision records (ADRs), telemetry platform roadmaps, and capacity/licensing forecast models.
Detection Engineering:
- Lead the full detection engineering lifecycle: content strategy, SIEM rule development and tuning, correlation logic, and content retirement within Splunk ES.
- Develop advanced SPL queries, dashboards, reports, and alerts supporting real-time threat monitoring and threat hunting.
- Build and tune Splunk ES notable event logic and risk-based alerting (RBA) to reduce false positives and improve detection fidelity.
- Analyze threat intelligence feeds and translate IOCs and MITRE ATT&CK-mapped TTPs into actionable detection content.
- Collaborate with Tier 1 and Tier 2 analysts to develop investigation playbooks and automated response workflows integrated with Splunk SOAR.
Incident Response & SOC Escalation:
- Serve as the senior technical escalation point for high-severity and complex security incidents escalated from Tier 1 and Tier 2 SOC analysts.
- Conduct proactive threat hunting across endpoints, networks, and cloud environments using hypothesis-driven methodologies.
- Perform digital forensics and memory analysis on compromised systems to determine scope, root cause, and attacker TTPs.
- Participate in red/purple team exercises to validate detection and response effectiveness; drive continuous improvement through post-incident reviews.
- Produce incident briefings and post-incident reports for technical and executive audiences.
Collaboration & Mentorship:
- Mentor Tier 1 and Tier 2 SOC analysts on advanced Splunk usage, detection engineering techniques, and threat hunting methodologies.
- Partner with CTS Cloud Engineering, DevSecOps, and Infrastructure teams to integrate security telemetry into CI/CD pipelines and cloud-native architectures.
- Brief senior leadership and the CISO on telemetry platform health, detection coverage gaps, and strategic roadmap decisions.
Required Qualifications:
- 10+ years of progressive information security experience, with a minimum of 5 years in a senior detection engineering, SIEM architecture, or SOC architecture role consistent with P5 (staff-level individual contributor) expectations.
- Demonstrated hands-on experience designing, deploying, and operating Splunk at enterprise scale: distributed/clustered environments, index cluster management, search head clustering, and ingest volumes of 500 GB+ per day.
- Deep Splunk proficiency: SPL development, Splunk Enterprise Security (ES) content authoring, data model acceleration, risk-based alerting (RBA), and Splunk SOAR integration.
- Practical experience integrating Amazon Security Lake (AWS Security Lake): OCSF schema design, AWS Lake Formation access controls, and query connectivity (Athena, Glue, or Splunk S3 inputs) as a telemetry source.
- Working knowledge of at least one complementary SIEM or telemetry platform beyond Splunk (e.g., Microsoft Sentinel, CrowdStrike Falcon LogScale, Google Chronicle/SecOps, or IBM QRadar).
- Hands-on experience with CTS-relevant security tooling: CrowdStrike Falcon (EDR), Tenable (vulnerability management), Imperva WAF, and Qualys for log onboarding and telemetry integration.
- Deep understanding of MITRE ATT&CK and MITRE D3FEND frameworks for detection-oriented threat modeling.
- Strong scripting and automation skills in Python, PowerShell, and/or Bash; experience with REST APIs for SIEM/SOAR integration and data pipeline automation.
- Experience with cloud security monitoring in both AWS and Azure environments, including native security services (AWS Security Hub, GuardDuty, CloudTrail; Azure Defender/Microsoft Sentinel).
- Excellent written and verbal communication skills, including demonstrated ability to produce executive-level briefings and architecture documentation.
Preferred Qualifications:
- Splunk Certified Architect (SCA) or Splunk Enterprise Security Certified Admin.
- AWS Security Specialty certification or equivalent demonstrated AWS security expertise.
- One or more of: GCIA, GCIH, GCFA, GREM, GCFE, or OSCP.
- Experience with Kubernetes-native logging architectures: Splunk Connect for Kubernetes (SCK), Fluentd, or Fluent Bit in production container environments.
- Familiarity with OCSF (Open Cybersecurity Schema Framework) and cross-platform security data normalization.
- Knowledge of OT/ICS security monitoring and log collection within NIST CSF 2.0-governed environments.
- Prior experience in PCI DSS-regulated environments (payment card), DoD/CMMC-regulated environments, or other critical infrastructure sectors.
- Experience with threat intelligence platforms (e.g., MISP, ThreatConnect, Recorded Future) and integrating TI feeds into SIEM detection pipelines.
- Contributions to the security community (conference presentations, open-source tooling, published research)
Did you find something suspicious?
Posted by
Swarupa
Self Employed at Growel Softech
Last Active: NA as recruiter has posted this job through third party tool.
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1645332