The Role
Engineers and maintains SIEM and Cribl telemetry pipelines, develops MITRE ATT&CK-aligned detections, onboards and validates log sources, tunes false positives, and creates queries, dashboards, and data models for SOC and incident response teams. Monitors ingestion health and pipeline performance, supports investigations, documents engineering processes, resolves telemetry issues, and mentors junior analysts and engineers on SIEM and Cribl practices.
Summary Generated by Built In
Duties & Responsibilities
- Engineer and maintain SIEM ingestion pipelines, including data connectors, parsers, normalization, and enrichment across endpoint, network, cloud, identity, and app telemetry sources.
- Build, tune, and update detection rules, correlation logic, and analytics aligned to MITRE ATT&CK, threat intelligence, and evolving TTPs.
- Operate and enhance Cribl Stream and Cribl Edge pipelines for log routing, transformation, filtering, enrichment, and delivery optimization.
- Support onboarding of new log sources, including schema mapping, troubleshooting ingestion failures, and validating data quality and completeness.
- Assist in reducing false positives and improving signaltonoise through SIEM tuning, enrichment enhancements, and Cribl workflow adjustments.
- Develop queries, dashboards, and data models used by SOC and IR teams for investigations, monitoring, and hunting.
- Monitor telemetry ingestion metrics, SIEM health, license usage, and Cribl pipeline performance; identify and resolve operational issues.
- Perform investigation support by validating detections, analyzing telemetry gaps, and implementing fixes to improve future coverage.
- Mentor junior analysts and engineers on SIEM query languages (KQL/SPL), detection development, logging best practices, and Cribl pipeline fundamentals.
- Maintain SIEM and telemetry documentation including data dictionaries, ingestion maps, detection catalogs, and engineering runbooks.
Requirements
Basic Qualifications
- Proficient in various cybersecurity frameworks and standards.
- Experience with security tools such as SIEM, firewalls, and intrusion detection systems.
Preferred Qualifications
- Relevant certifications (e.g., CISSP, CISM, CEH).
- Master’s degree in Cybersecurity or related field.
Skills Required
- Proficiency in cybersecurity frameworks and standards
- Experience with security tools such as SIEM, firewalls, and intrusion detection systems
- Relevant cybersecurity certifications, such as CISSP, CISM, or CEH
- Master's degree in Cybersecurity or a related field
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Staples India is Staples’ technology and innovation hub in Chennai, building platforms, systems, and digital solutions that support the company’s global operations and future of work. Staples serves consumers and businesses with workplace products and services, including office supplies, janitorial products, technology, furniture, breakroom essentials, print and marketing, shipping, travel, and promotional offerings. Its India teams focus on engineering, eCommerce, process optimization, and enterprise solutions.

.jpeg)







