Security Resource — SIEM at Croyant Technologies Pvt Ltd
About this role
Job Title: Security Resource — SIEM
Key Responsibilities
•Own the full lifecycle management of the Seceon aiSIEM platform or other
SIEM/SOAR equivalents — initial configuration, log source onboarding,
correlation rule development, threat intelligence feed integration, policy tuning,
and ongoing health maintenance
•Lead threat analysis and security operations for the DoP IT 2.0 environment:
continuously monitor SIEM dashboards, investigate high-fidelity alerts,
perform threat hunting, and manage the response to confirmed security
incidents through the ITSM process
•Onboard new log sources as the environment expands: define ingestion
requirements, co-ordinate with domain teams (network, OS, application, DB)
to configure syslog/SNMP/API feeds, validate completeness, and tune
correlation rules to reduce false positives
•Develop and maintain SIEM-specific SOPs and run books: playbooks for
common alert types, major incident response procedures, threat containment
steps, and SOAR-style workflow documentation for repeatable investigation
tasks
•Manage log retention in alignment with security policy; flag to the Operations
Manager and HPE Architect if declared policy deviates from the contractual
sizing
•Co-ordinate with SIEM OEM for product patches, custom rule development,
and escalation of platform-level defects
•Produce security operations reports for the monthly SLA cycle and ad-hoc
DoP requests: threat event summaries, alert volume trends, detection rule
effectiveness, and incident response timelines
•Support VAPT activities and security audits by providing SIEM log evidence,
alert history, and investigation records
Skills & Competencies
•Deep expertise in Seceon aiSIEM or equivalent SIEM platforms (Splunk,
QRadar, Microsoft Sentinel, ArcSight, Logrhythm); proficiency in log source
integration, correlation rule authoring, and alert tuning
•Threat detection frameworks: MITRE ATT&CK mapping, threat hunting
techniques, and IOC/IOA analysis
•Log source breadth: syslog, Windows Event Logs, netflow/IPFIX, API-based
ingestion, and endpoint telemetry
•SOAR concepts: scripted playbook development for automated response and
case management (even where a formal SOAR is not deployed)
•Security incident response: triage, containment, forensic log analysis, and
structured RCA documentation
Preferred Certifications
CEH / GCIA / CompTIA Security+ or equivalent; Seceon platform training
(preferred)
Min. Qualification
Min. Experience
More than 5 years of hands-on experience in IT security operations including
SIEM administration, threat detection, SOC operations, and security incident
response
Applying takes you to the AtBench listing where you can complete your application.