Overview
The Senior Detection Engineer is a senior technical contributor accountable for SIEM delivery and detection content engineering across the enterprise. The role designs, builds, tests, deploys, tunes, and continuously improves detections using SIEM, NDR, EDR, cloud, identity, network, endpoint, application, and email telemetry.
What you'll do
- Drive the design, implementation, maintenance, and optimization of the enterprise SIEM platform.
- Define and maintain the SIEM delivery roadmap in line with Global Security Organization strategy and business priorities.
- Onboard security-relevant log sources with appropriate parsing, normalization, enrichment, correlation, retention, and searchability.
- Monitor and improve platform availability, performance, scalability, and capacity.
- Keep SIEM components on supported versions and ensure relevant patches and updates are applied.
- Troubleshoot data ingestion, pipeline, parsing, indexing, correlation, and platform performance issues.
- Maintain engineering standards, technical documentation, architecture artifacts, and operating procedures for the SIEM environment.
- Identify security-control and detection-coverage gaps and recommend prioritized improvements.
- Define security key performance indicators and engineering metrics for SIEM and detection capabilities.
- Maintain documented review of detection exceptions, accepted risks, suppressions, exclusions, and rule changes.
- Link engineering outcomes to the Global Security Organization’s strategic roadmap and business needs.
- Use AI-enabled security tools and automation to improve threat detection, incident response, and operational efficiency across the cybersecurity environment.
- Identify opportunities to automate repetitive security tasks, reduce manual effort, and help build smarter, faster, and more scalable cyber operations.
- Apply AI and data-driven insights to analyze security events, correlate signals, and support proactive protection of systems, data, and intellectual property.
What you'll need
- 4 to 8 years in cybersecurity, security engineering, SIEM engineering, detection engineering, or incident response.
- BE/BTech graduation.
- Strong hands-on experience operating and engineering an enterprise SIEM platform.
- Experience integrating and analyzing telemetry from network, endpoint, cloud, identity, application, and email platforms.
- Proven ability to convert threat intelligence, adversary behaviors, and incidents into technical detection content.
- Data pipeline fundamentals, including log ingestion, parsing, normalization, enrichment, schema mapping, correlation, indexing, retention, and data quality.
- Scripting with Python, PowerShell, Bash, or comparable, applied to automation and content engineering.
- Hands-on use of APIs, Git or another version-control platform, and structured content-development practices.
- Strong analytical, troubleshooting, and technical-writing capabilities.
- Proficiency in one or more of KQL, SPL, EQL, ES|QL, SQL, Lucene, Sigma, or equivalent.
- Knowledge of next-generation firewalls such as Cisco or Palo Alto Networks, plus firewall management and monitoring solutions.
- Knowledge of endpoint security tools, including EDR, PAM, PKI, and DLP.
- Knowledge of web proxy and Secure Web Gateway technologies.
- Knowledge of remote-access and SSL VPN solutions.
- Knowledge of Intrusion Prevention Systems such as Cisco Firepower or similar platforms.
- Knowledge of IPsec tunnels, site-to-site connectivity, and business-to-business interconnects.
- Knowledge of stateful inspection, TCP/IP, DNS, HTTP/HTTPS, web protocols, and general networking concepts.
- Knowledge of Network Detection and Response technologies, SSL/TLS certificates, certificate exchange, PKI, and certificate management.
- Knowledge of endpoint protection and EDR technologies such as SentinelOne, CrowdStrike, Carbon Black, or Cylance.
- Knowledge of network data loss prevention technologies such as DarkTrace, McAfee Access control, data classification, and data-loss-prevention concepts.
- Knowledge of cloud, identity, application, email, and endpoint security telemetry.
- Understanding of AI/ML concepts and a strong willingness to learn and apply AI tools to improve cybersecurity operations, threat detection, and response efficiency.
- An automation-first mindset with the ability to identify repetitive manual tasks and leverage scripting, workflow automation, and AI-enabled tools to secure Micron more effectively.
Nice to have
- Zscaler familiarity is preferred.
Details
- Location: Hyderabad, India.
Read the full description and apply on the company’s own careers page.