The Role
Architects and optimizes SIEM and Cribl telemetry pipelines; onboards diverse security data sources; develops MITRE ATT&CK-aligned detections; tunes alerts; builds dashboards and hunting queries; monitors ingestion health, costs, and coverage; troubleshoots pipeline and detection failures; mentors engineers and analysts; and maintains technical documentation, runbooks, metrics, and governance standards.
Summary Generated by Built In
Duties & Responsibilities
- Architect and optimize SIEM platforms (e.g., Microsoft Sentinel, Splunk), including ingestion pipelines, parsing/normalization, enrichment, and correlation logic.
- Engineer and operate Cribl Stream and Cribl Edge for log routing, filtering, transformation, enrichment, data reduction, and destination fanout (SIEM, data lake, cold storage).
- Design and maintain telemetry onboarding with schema mapping, collectors/agents, connectors, API integrations, replay, and edge collection for diverse sources (endpoint, network, cloud, identity, app).
- Develop advanced detections and analytics (rules, queries, correlations) aligned to MITRE ATT&CK, emerging TTPs, and threat intelligence; measure detection efficacy and coverage.
- Lead systematic alert tuning to reduce false positives and improve signaltonoise, leveraging Cribl pipelines and SIEM analytics to standardize high-fidelity events.
- Build investigation assets (dashboards, hunting queries, data models) that accelerate SOC workflows and rootcause analysis across telemetry domains.
- Monitor ingestion health and cost (EPS/GB/day, license utilization), implement Criblbased data controls (sampling, routing, suppression) to ensure reliability and budget adherence.
- Perform RCA on detection gaps and pipeline failures; implement durable fixes in Cribl routes/pipelines and SIEM parsing/enrichment layers.
- Mentor engineers and analysts on KQL/SPL, detection engineering patterns, Cribl pipeline design, and telemetry best practices; conduct peer reviews and standards governance.
- Maintain documentation: data dictionaries, detection catalogs, Cribl pipeline/runbooks, ingestion maps, and metrics reporting on coverage, fidelity, MTTR, and pipeline SLOs.
Requirements
Basic Qualifications
- Solid understanding of network protocols, data protection mechanisms, and threat landscapes
- Hands-on experience with security systems, including firewalls, intrusion detection systems, anti-virus software, etc.
Preferred Qualifications
- Industry-recognized certifications (e.g., CISSP, CISM, CEH)
- Master’s degree in Cybersecurity or a related field
Skills Required
- Solid understanding of network protocols, data protection mechanisms, and threat landscapes
- Hands-on experience with security systems, including firewalls, intrusion detection systems, and antivirus software
- Industry-recognized certification such as CISSP, CISM, or CEH
- Master's degree in Cybersecurity or a related field
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Staples India is Staples’ technology and innovation hub in Chennai, building platforms, systems, and digital solutions that support the company’s global operations and future of work. Staples serves consumers and businesses with workplace products and services, including office supplies, janitorial products, technology, furniture, breakroom essentials, print and marketing, shipping, travel, and promotional offerings. Its India teams focus on engineering, eCommerce, process optimization, and enterprise solutions.








