Track Lead - Security Investigations, SIEM
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · Datavetenskap · Dataanalys
I korthet
Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional security controls. This role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.
Ansvarsområden
- Conduct hypothesis-based and IOC-driven threat hunting across Endpoint (EDR/XDR), SIEM/Log Management platforms, Network telemetry (NDR), Identity logs (AD/Entra ID), and Cloud platforms (Azure, AWS, M365).
- Identify stealthy and advanced threats including Living off the Land (LotL) techniques, Advanced Persistent Threats (APTs), lateral movement, privilege escalation, and insider threat indicators.
- Develop and execute MITRE ATT&CK-aligned hunting hypotheses.
- Convert hunting findings into security incidents, new detection rules (SIEM/EDR/XDR), and change or service requests for misconfigurations or logging gaps.
- Collaborate with SOC, Incident Response, and Threat Intelligence teams.
- Produce hunting reports and KPIs such as dwell time reduction, hunts to detections, and incidents generated.
Krav
- Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM).
- Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex).
- Proficiency in KQL/SPL/advanced hunting queries.
- Deep understanding of MITRE ATT&CK techniques and TTPs.
- Strong OS knowledge: Windows, Linux, macOS.
- Basic scripting skills (PowerShell/Python preferred).
- Cloud security exposure (Azure, AWS, M365 Defender).
- 6+ years in SOC/Threat Detection, with 2+ years in threat hunting.
- Strong analytical and investigative mindset.
- Client facing reporting and presentation skills.
- Willingness to work in 24x7 SOC environments.
Förmåner
- Supercharge your potential at HCLTech.
- Find your career and spark at a company that puts people first.
- Global technology company with over 223,000 people across 60 countries.
- Work with clients across Financial Services, Manufacturing, Life Sciences & Healthcare, Technology & Services, Telecom & Media, Retail & CPG, and Public Services.
#Security Investigations#SIEM#Threat Hunting#Cybersecurity#SOC#Endpoint Security#Network Security#Cloud Security#Incident Response#Threat Intelligence