Track Lead - Security Investigations, SIEM

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Data Science · Data Analysis

In short

Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional security controls. This role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.

Responsibilities

  • Conduct hypothesis-based and IOC-driven threat hunting across Endpoint (EDR/XDR), SIEM/Log Management platforms, Network telemetry (NDR), Identity logs (AD/Entra ID), and Cloud platforms (Azure, AWS, M365).
  • Identify stealthy and advanced threats including Living off the Land (LotL) techniques, Advanced Persistent Threats (APTs), lateral movement, privilege escalation, and insider threat indicators.
  • Develop and execute MITRE ATT&CK-aligned hunting hypotheses.
  • Convert hunting findings into security incidents, new detection rules (SIEM/EDR/XDR), and change or service requests for misconfigurations or logging gaps.
  • Collaborate with SOC, Incident Response, and Threat Intelligence teams.
  • Produce hunting reports and KPIs such as dwell time reduction, hunts to detections, and incidents generated.

Requirements

  • Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM).
  • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex).
  • Proficiency in KQL/SPL/advanced hunting queries.
  • Deep understanding of MITRE ATT&CK techniques and TTPs.
  • Strong OS knowledge: Windows, Linux, macOS.
  • Basic scripting skills (PowerShell/Python preferred).
  • Cloud security exposure (Azure, AWS, M365 Defender).
  • 6+ years in SOC/Threat Detection, with 2+ years in threat hunting.
  • Strong analytical and investigative mindset.
  • Client facing reporting and presentation skills.
  • Willingness to work in 24x7 SOC environments.

Benefits

  • Supercharge your potential at HCLTech.
  • Find your career and spark at a company that puts people first.
  • Global technology company with over 223,000 people across 60 countries.
  • Work with clients across Financial Services, Manufacturing, Life Sciences & Healthcare, Technology & Services, Telecom & Media, Retail & CPG, and Public Services.
#Security Investigations#SIEM#Threat Hunting#Cybersecurity#SOC#Endpoint Security#Network Security#Cloud Security#Incident Response#Threat Intelligence
HCLTech Logo

Company

HCLTech

Job Posted

3 weeks ago

Employment Type

Full Time

WorkMode

On Site

Experience Level

Senior

Locations

Noida, India

Applicants

Be an early applicant