Sr Subject Matter Expert (Support&Ops)
India
Job Description
Sr Subject Matter Expert (Support&Ops)
Pune, Maharashtra

Job Summary

Years of Experience

  • 12+ years of experience in SIEM engineering, Splunk administration, security analytics, detection engineering, and enterprise log-management environments.

General Description

  • Serve as the L3 SME for Customer’s Splunk Cloud managed service, responsible for advanced troubleshooting, engineering, optimization, and technical governance. 
  • Lead complex data onboarding, detection-content engineering, advanced dashboarding, alert tuning, performance optimization, and RCA support. 
  • Provide technical oversight to L2 engineers and collaborate with Customer, SOC/MSSP, IAM, PAM, AppSec, DevOps, network, cloud, and application teams. 

 

 

Key Responsibilities

Technical Requirements

  • Hands-on experience with Splunk Enterprise and/or Splunk Cloud in enterprise environments. 
  • Experience with SPL searches, dashboards, reports, alerts, field extractions, sourcetypes, indexes, and knowledge objects. 
  • Experience in log-source onboarding, ingestion validation, parsing, field mapping, data-quality checks, and pipeline troubleshooting. 
  • Knowledge of SIEM operations, security monitoring, incident investigation, RCA evidence, and operational reporting. 
  • Experience integrating Splunk with IAM, PAM, SSO, EDR, cloud, network-security, application, and infrastructure data sources. 
  • Experience with ServiceNow/Jira, incident, request, change, and problem management processes. 
  • Ability to maintain use-case catalogues, data-source inventories, dashboard inventories, runbooks, and service metrics. 
  • Advanced SPL development and optimization, data models, accelerated searches, correlation searches, macros, lookups, and enterprise-scale dashboard design. 
  • Strong experience in detection engineering, MITRE ATT&CK mapping, use-case lifecycle management, tuning methodology, and security-content governance. 
  • Experience troubleshooting complex ingestion architecture, heavy forwarders, universal forwarders, HEC, APIs, cloud integrations, and data-routing issues. 
  • Knowledge of Splunk Cloud architecture, search performance, ingestion forecasting, retention, index strategy, and cost/license optimization. 
  • Ability to lead RCA, problem management, technical reviews, platform upgrades, automation, and continuous-improvement initiatives. 
  • Experience with Python, REST APIs, Git, CI/CD, and automation of Splunk administration and content deployment. 

Soft Skills

  • Excellent communication and presentation skills.
  • Strong problem-solving and critical thinking skills.
  • Exceptional project management and organizational abilities.
  • Team collaboration and leadership skills.
  • Client-focused approach with a commitment to delivering exceptional customer service.

Certifications (Good to have)

Good to have relevant certificates like (any of the below):

  • Splunk Enterprise Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Security Certified Admin. 
  • CISSP, GCIA, GCIH, CySA+, or equivalent security certification is preferred.

Educational Qualifications

  • University degree in IT or/and IT Security.
  • Bachelor’s degree in computer science/ IT or any relevant fields.

 

Skill Requirements

Technical Requirements

  • Hands-on experience with Splunk Enterprise and/or Splunk Cloud in enterprise environments. 
  • Experience with SPL searches, dashboards, reports, alerts, field extractions, sourcetypes, indexes, and knowledge objects. 
  • Experience in log-source onboarding, ingestion validation, parsing, field mapping, data-quality checks, and pipeline troubleshooting. 
  • Knowledge of SIEM operations, security monitoring, incident investigation, RCA evidence, and operational reporting. 
  • Experience integrating Splunk with IAM, PAM, SSO, EDR, cloud, network-security, application, and infrastructure data sources. 
  • Experience with ServiceNow/Jira, incident, request, change, and problem management processes. 
  • Ability to maintain use-case catalogues, data-source inventories, dashboard inventories, runbooks, and service metrics. 
  • Advanced SPL development and optimization, data models, accelerated searches, correlation searches, macros, lookups, and enterprise-scale dashboard design. 
  • Strong experience in detection engineering, MITRE ATT&CK mapping, use-case lifecycle management, tuning methodology, and security-content governance. 
  • Experience troubleshooting complex ingestion architecture, heavy forwarders, universal forwarders, HEC, APIs, cloud integrations, and data-routing issues. 
  • Knowledge of Splunk Cloud architecture, search performance, ingestion forecasting, retention, index strategy, and cost/license optimization. 
  • Ability to lead RCA, problem management, technical reviews, platform upgrades, automation, and continuous-improvement initiatives. 
  • Experience with Python, REST APIs, Git, CI/CD, and automation of Splunk administration and content deployment. 

Soft Skills

  • Excellent communication and presentation skills.
  • Strong problem-solving and critical thinking skills.
  • Exceptional project management and organizational abilities.
  • Team collaboration and leadership skills.
  • Client-focused approach with a commitment to delivering exceptional customer service.

Certifications (Good to have)

Good to have relevant certificates like (any of the below):

  • Splunk Enterprise Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Security Certified Admin. 
  • CISSP, GCIA, GCIH, CySA+, or equivalent security certification is preferred.

Educational Qualifications

  • University degree in IT or/and IT Security.
  • Bachelor’s degree in computer science/ IT or any relevant fields.

 

Other Requirements

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.