Track Lead - Security Analysis, SIEM
Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · DevOps
In short
As a Track Lead for Security Analysis and SIEM, you will be responsible for proactively identifying, investigating, and mitigating advanced cyber threats. This role focuses on hypothesis-driven threat hunting across various environments like endpoint, network, and cloud to enhance detection maturity.
Responsibilities
- Conduct hypothesis-based and IOC-driven threat hunting across Endpoint (EDR/XDR), SIEM/Log Management, Network Telemetry (NDR), Identity logs (AD/Entra ID), and Cloud platforms (Azure, AWS, M365).
- Identify stealthy and advanced threats including Living off the Land (LotL) techniques, Advanced Persistent Threats (APTs), lateral movement, privilege escalation, and insider threat indicators.
- Develop and execute MITRE ATT&CK-aligned hunting hypotheses.
- Convert hunting findings into security incidents, new detection rules (SIEM/EDR/XDR), and change or service requests.
- Collaborate with SOC, Incident Response, and Threat Intelligence teams.
- Produce hunting reports and KPIs such as dwell time reduction, hunts to detections, and incidents generated.
Requirements
- 6+ years in SOC/Threat Detection, with 2+ years in threat hunting.
- Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM).
- Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex).
- Proficiency in KQL/SPL/advanced hunting queries.
- Deep understanding of MITRE ATT&CK techniques and TTPs.
- Strong OS knowledge: Windows, Linux, macOS.
- Basic scripting skills (PowerShell/Python preferred).
- Cloud security exposure (Azure, AWS, M365 Defender).
- Strong analytical and investigative mindset.
- Client-facing reporting and presentation skills.
- Willingness to work in 24x7 SOC environments.
Benefits
- Supercharge your potential at HCLTech.
- Find your career and your spark at a company that puts its people first.
- Global technology company with over 223,000 people across 60 countries.
- Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.
#Security Analysis#SIEM#Cyber Threats#Threat Hunting#Endpoint Security#Network Security#Cloud Security#SOC#Incident Response#Threat Intelligence