HamburgerMenu
hirist

Job Description

Senior Security Telemetry Architect

NP : Very immediate joiners

Work Location : Hyderabad

Key Responsibilities :

Telemetry Platform Architecture :

- Design and own the Splunk architecture: distributed/clustered indexer and search head topology, SmartStore data tiering, forwarder management, and capacity planning for CTS-scale ingest.

- Define and govern log source onboarding standards, parsing/transforms, and Common Information Model (CIM) compliance across all data inputs.

- Architect and implement integration with Amazon Security Lake (AWS Security Lake): Open Cybersecurity Schema Framework (OCSF) normalization, AWS Lake Formation permissions, and Athena/Glue query connectivity to Splunk.

- Evaluate and maintain knowledge of complementary telemetry platforms including Microsoft Sentinel, CrowdStrike Falcon LogScale, Google Chronicle/SecOps, and IBM QRadar; provide platform comparison analysis and integration recommendations as the security stack evolves.

- Lead Kubernetes-native log collection design using Splunk Connect for Kubernetes (SCK), Fluentd, or Fluent Bit for CTS container environments.

- Produce architecture decision records (ADRs), telemetry platform roadmaps, and capacity/licensing forecast models.

Detection Engineering:

- Lead the full detection engineering lifecycle: content strategy, SIEM rule development and tuning, correlation logic, and content retirement within Splunk ES.

- Develop advanced SPL queries, dashboards, reports, and alerts supporting real-time threat monitoring and threat hunting.

- Build and tune Splunk ES notable event logic and risk-based alerting (RBA) to reduce false positives and improve detection fidelity.

- Analyze threat intelligence feeds and translate IOCs and MITRE ATT&CK-mapped TTPs into actionable detection content.

- Collaborate with Tier 1 and Tier 2 analysts to develop investigation playbooks and automated response workflows integrated with Splunk SOAR.

Incident Response & SOC Escalation:

- Serve as the senior technical escalation point for high-severity and complex security incidents escalated from Tier 1 and Tier 2 SOC analysts.

- Conduct proactive threat hunting across endpoints, networks, and cloud environments using hypothesis-driven methodologies.

- Perform digital forensics and memory analysis on compromised systems to determine scope, root cause, and attacker TTPs.

- Participate in red/purple team exercises to validate detection and response effectiveness; drive continuous improvement through post-incident reviews.

- Produce incident briefings and post-incident reports for technical and executive audiences.

Collaboration & Mentorship:

- Mentor Tier 1 and Tier 2 SOC analysts on advanced Splunk usage, detection engineering techniques, and threat hunting methodologies.

- Partner with CTS Cloud Engineering, DevSecOps, and Infrastructure teams to integrate security telemetry into CI/CD pipelines and cloud-native architectures.

- Brief senior leadership and the CISO on telemetry platform health, detection coverage gaps, and strategic roadmap decisions.

Required Qualifications:

- 10+ years of progressive information security experience, with a minimum of 5 years in a senior detection engineering, SIEM architecture, or SOC architecture role consistent with P5 (staff-level individual contributor) expectations.

- Demonstrated hands-on experience designing, deploying, and operating Splunk at enterprise scale: distributed/clustered environments, index cluster management, search head clustering, and ingest volumes of 500 GB+ per day.

- Deep Splunk proficiency: SPL development, Splunk Enterprise Security (ES) content authoring, data model acceleration, risk-based alerting (RBA), and Splunk SOAR integration.

- Practical experience integrating Amazon Security Lake (AWS Security Lake): OCSF schema design, AWS Lake Formation access controls, and query connectivity (Athena, Glue, or Splunk S3 inputs) as a telemetry source.

- Working knowledge of at least one complementary SIEM or telemetry platform beyond Splunk (e.g., Microsoft Sentinel, CrowdStrike Falcon LogScale, Google Chronicle/SecOps, or IBM QRadar).

- Hands-on experience with CTS-relevant security tooling: CrowdStrike Falcon (EDR), Tenable (vulnerability management), Imperva WAF, and Qualys for log onboarding and telemetry integration.

- Deep understanding of MITRE ATT&CK and MITRE D3FEND frameworks for detection-oriented threat modeling.

- Strong scripting and automation skills in Python, PowerShell, and/or Bash; experience with REST APIs for SIEM/SOAR integration and data pipeline automation.

- Experience with cloud security monitoring in both AWS and Azure environments, including native security services (AWS Security Hub, GuardDuty, CloudTrail; Azure Defender/Microsoft Sentinel).

- Excellent written and verbal communication skills, including demonstrated ability to produce executive-level briefings and architecture documentation.

Preferred Qualifications:

- Splunk Certified Architect (SCA) or Splunk Enterprise Security Certified Admin.

- AWS Security Specialty certification or equivalent demonstrated AWS security expertise.

- One or more of: GCIA, GCIH, GCFA, GREM, GCFE, or OSCP.

- Experience with Kubernetes-native logging architectures: Splunk Connect for Kubernetes (SCK), Fluentd, or Fluent Bit in production container environments.

- Familiarity with OCSF (Open Cybersecurity Schema Framework) and cross-platform security data normalization.

- Knowledge of OT/ICS security monitoring and log collection within NIST CSF 2.0-governed environments.

- Prior experience in PCI DSS-regulated environments (payment card), DoD/CMMC-regulated environments, or other critical infrastructure sectors.

- Experience with threat intelligence platforms (e.g., MISP, ThreatConnect, Recorded Future) and integrating TI feeds into SIEM detection pipelines.

- Contributions to the security community (conference presentations, open-source tooling, published research)

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...