Track Lead - Security Investigations, SIEM
India
Job Description
Track Lead - Security Investigations, SIEM
Noida, Uttar Pradesh

Job Summary

Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.

Key Responsibilities

Conduct hypothesis-based and IOC-driven threat hunting across: o Endpoint (EDR/XDR) o SIEM / Log Management platforms o Network telemetry (NDR) o Identity logs (AD / Entra ID) o Cloud platforms (Azure, AWS, M365) • Identify stealthy and advanced threats, including: o Living off the Land (LotL) techniques o Advanced Persistent Threats (APTs) o Lateral movement and privilege escalation o Insider threat indicators • Develop and execute MITRE ATT&CK;–aligned hunting hypotheses • Convert hunting findings into: o Security incidents o New detection rules (SIEM / EDR / XDR) o Change or service requests (misconfigurations, logging gaps) • Collaborate with SOC, Incident Response, and Threat Intelligence teams • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated)

Skill Requirements

Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM) • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex) • Proficiency in KQL / SPL / advanced hunting queries • Deep understanding of MITRE ATT&CK; techniques and TTPs • Strong OS knowledge: Windows, Linux, macOS • Basic scripting skills (PowerShell / Python preferred) • Cloud security exposure (Azure, AWS, M365 Defender) Experience & Soft Skills • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting • Strong analytical and investigative mindset • Client facing reporting and presentation skills • Willingness to work in 24×7 SOC environments

Other Requirements

Role Overview Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity. Key Responsibilities • Conduct hypothesis-based and IOC-driven threat hunting across: o Endpoint (EDR/XDR) o SIEM / Log Management platforms o Network telemetry (NDR) o Identity logs (AD / Entra ID) o Cloud platforms (Azure, AWS, M365) • Identify stealthy and advanced threats, including: o Living off the Land (LotL) techniques o Advanced Persistent Threats (APTs) o Lateral movement and privilege escalation o Insider threat indicators • Develop and execute MITRE ATT&CK;–aligned hunting hypotheses • Convert hunting findings into: o Security incidents o New detection rules (SIEM / EDR / XDR) o Change or service requests (misconfigurations, logging gaps) • Collaborate with SOC, Incident Response, and Threat Intelligence teams • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated) Technical Skills • Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM) • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex) • Proficiency in KQL / SPL / advanced hunting queries • Deep understanding of MITRE ATT&CK; techniques and TTPs • Strong OS knowledge: Windows, Linux, macOS • Basic scripting skills (PowerShell / Python preferred) • Cloud security exposure (Azure, AWS, M365 Defender) Experience & Soft Skills • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting • Strong analytical and investigative mindset • Client facing reporting and presentation skills • Willingness to work in 24×7 SOC environments

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.