SeniorAdministrator - Security Analysis, SIEM
India
Job Description
SeniorAdministrator - Security Analysis, SIEM
Chennai, Tamil Nadu

Job Summary

Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor\'s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID

Key Responsibilities

Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor\'s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID

 

Skill Requirements

: Key Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor\'s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID

 

Other Requirements

 Responsibilities Incident Detection & Response • Monitor and investigate security alerts from Taegis, Defender as well as user or third-party reported incidents. • Perform initial triage and analysis of suspicious events and potential security incidents. • Determine incident severity, scope, and business impact. • Contain security incidents through actions such as: o Account disablement o Password resets o Session revocation o Device isolation o IP and domain blocking • Escalate complex or high-severity incidents to senior security personnel. Investigation & Analysis • Analyze endpoint, network, identity, and cloud telemetry. • Correlate indicators of compromise (IOCs) with threat intelligence sources. • Identify root causes and attack vectors. • Conduct malware investigations and support forensic analysis activities. • Track attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK;. Incident Documentation • Maintain detailed incident records and case documentation. • Create incident reports detailing findings, actions taken, and business impact. • Ensure evidence is collected, preserved, and documented appropriately. • Participate in post-incident reviews and lessons-learned sessions. Collaboration • Coordinate with IT Operations, Service Desk, Infrastructure, Network, and Cloud teams during investigations. • Communicate incident status to stakeholders and management. • Support major incident response activities and virtual war room operations during significant security events. Continuous Improvement • Contribute to development of SOC playbooks and response procedures. • Recommend improvements to detection rules, monitoring coverage, and response workflows. • Assist in threat hunting and security control validation activities. • Stay current with emerging threats, vulnerabilities, and industry best practices. Required Qualifications Education • Bachelor\'s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent experience. Experience • 2–5+ years of cybersecurity, SOC, incident response, or security operations experience. • Experience investigating security incidents in enterprise environments. • Familiarity with Windows, Linux, cloud platforms, and enterprise networking. Technical Skills • SIEM technologies • EDR/XDR platforms (Taegis , Microsoft Defender, CrowdStrike, SentinelOne, etc.) • Email security technologies • Identity platforms such as Active Directory and Entra ID
Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.