Company : TCSSkill : Google SecOpsExperience : 4 to 15 YearsLocation : Bengaluru and ChennaiInterview Mode : Face to Face (Walkin)Interview Date : 13th June 2026 (Saturday)
Job Description
SIEM Engineering & Platform ManagementDesign, deploy, configure, and manage Google SecOps (Chronicle SIEM) environmentsOnboard and normalize log sources including:
- Network devices (firewalls, proxies, IDS/IPS)
- Endpoint security solutions
- Cloud platforms (GCP, AWS, Azure)
- Identity and SaaS applications
- Develop and maintain parsers, ingestion pipelines, and data retention strategies
- Detection Engineering & Use Case Development
- Develop, tune, and optimize detection rules using YARA‑LCreate security use cases mapped to MITRE ATT&CKReduce false positives through continuous tuning and baselining
- Perform proactive threat hunting using Chronicle search capabilities
- Incident Support & SOC Enablement
- Support SOC teams with alert triage, investigation queries, and workflows
- Build dashboards, visualizations, and reports for security operations
- Assist in root cause analysis and post-incident improvement activities
- Automation & Integration
- Integrate Chronicle with security tools such as:SOAR platforms
- Ticketing systems (ServiceNow, Jira)
- EDR/XDR solutions
- Develop automation and enrichment workflows using APIs and scripting
- Continuous Improvement & Governance
- Ensure SIEM solution aligns with security standards and compliance needs
- Document use cases, detection logic, ingestion processes, and runbooks
- Stay current with evolving threats and Google Sec
- Ops capabilities
- Required Skills & Experience
Technical Skills
- Strong experience with Google Sec
- Ops / Chronicle SIEMProficiency in YARA‑L rule development
- Solid understanding of:SIEM architecture and log lifecycle
- Security event correlation and analytics
- MITRE ATT&CK framework
- Experience with cloud security logging (GCP preferred)
- Knowledge of networking, OS concepts, and security controls
- Scripting skills (Python, Bash, or similar are preferred)
- Security Domain Knowledge
- Incident detection and response
- Threat hunting and adversary behavior
- Malware, phishing, and insider threat analysis
- Preferred / Nice‑to‑Have
Skills
- Experience with SOAR tools (Cortex XSOAR, Chronicle SOAR, etc.)
- Certifications such as:
- Google Cloud Security Engineer
- GCED / GCIH / GCIACISSP or equivalent
- Experience working in SOC, MSSP, or large enterprise environments
- Exposure to Compliance frameworks (ISO 27001, SOC2, PCI‑DSS)