TC

SOC - SIEM Google Secops, Google Chronicle

Accepting applications

Tata Consultancy Services · Hyderabad, Telangana, India

Full-Time Mid_senior PythonSOC
Posted
3d ago
Category
Design
Experience
Mid_senior
Country
India
Role: SOC SIEM- Google Secops
Experience Range: 7 to 10
Interview Mode: Virtual Interview (13-Aug)
Location: Hyderabad

Job Description:
Google Chronicle SIEM Engineer , SOC Automation Specialist & Platform management
We are seeking a highly skilled Google Chronicle SIEM Engineer with expertise in SOC automation to enhance our detection capabilities and reduce false positives across the security landscape. The ideal candidate will be responsible for designing, developing, and maintaining advanced detection use cases, automation workflows, and integrations to strengthen our overall security posture and improve operational efficiency within the SOC environment.
Tools:
Google Chronical SIEM
Bind plane
Cribl
Key Responsibilities
Design, implement, and optimize Google Chronicle SIEM for scalable log ingestion, parsing, normalization, and enrichment.
Create and updating correlation rules and use cases
Develop and fine-tune detection rules, parsers, and correlation logic to improve threat detection accuracy.
Integrate diverse log sources including firewalls, endpoint security, cloud services, IAM, ,network devices and etc.,.
Build and maintain custom parsers and dashboards to enhance visibility into security events.
Collaborate with threat hunting and detection engineering teams to identify and implement new detection logic.
Design and implement automation workflows (SOAR-based or API-based) to reduce analyst workload and response time.
Automate alert triage, enrichment, and response actions using scripts, playbooks, or orchestration tools.
Integrate Google Chronicle with automation platforms (e.g., Cortex XSOAR, Splunk SOAR, Swimlane, or custom Python-based frameworks).
Bindplane :
Deploy, configure, and manage Bind Plane agents across servers and cloud workloads.
Set up data ingestion from multiple sources (Windows, Linux, databases, firewalls, cloud services).
Normalize data schemas and forward logs to SIEM or observability tools (Chronicle, Elastic, Splunk).
Configure pipelines for log transformation, labeling, and enrichment.
Implement monitoring and alerts for agent health, performance, and log ingestion failures.
Show more Show less