Flag job

Report

Cyber Threat Detection Engineer

Min Experience

1 years

Location

Mumbai, Navi Mumbai

JobType

full-time

About the job

Info This job is sourced from a job board

About the role

In this role, you will assist in designing, developing, and tuning security detections to identify potential threats targeting our enterprise IT & OT environments. You will work primarily with Splunk SIEM and a variety of data sources to ensure effective monitoring and alerting across endpoints, networks, and applications. This is an excellent opportunity to grow your skills in cybersecurity engineering, threat detection, and security analytics while collaborating with experienced analysts, threat hunters, and incident responders. You will also be responsible for: Detection Engineering & Development • Assisting in creating, testing, and deploying security detection rules and use cases in Splunk SIEM. • Developing queries using Splunk Search Processing Language (SPL) to identify suspicious activities and potential threats. • Participating in tuning existing alerts to minimize false positives and improve detection accuracy. • Supporting the creation of detection logic aligned to frameworks such as MITRE ATT&CK and industry best practices. Security Monitoring & Threat Analysis • Monitoring security alerts and reports to validate detection performance and identify areas for improvement. • Conducting basic threat analysis to understand attack patterns and adversary behaviors. • Collaborating with incident response and threat hunting teams to refine detections based on real-world incidents and emerging threats. Data Integration & Enrichment • Assisting in onboarding and validating new log sources into Splunk. • Supporting enrichment of detection logic with threat intelligence feeds, asset context, and other relevant data points. Collaboration & Documentation • Working closely with senior detection engineers, security analysts, and IT teams. • Document detection logic, use case requirements, tuning procedures, and validation results. • Participating in security operations process improvement initiatives.

About the company

We are an energy technology company that provides solutions to energy and industrial customers worldwide. Built on a century of experience and conducting business in over 120 countries, our innovative technologies and services are taking energy forward – making it safer, cleaner and more efficient for people and the planet.

Skills

splunk
security
cybersecurity
threat detection
security analytics
security monitoring
data integration
scripting
python