SOC Detection Engineering & Threat Intelligence
Indexed description
HCLTech is a global technology company, home to 219,000+ people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services.
Our purpose is to bring together the best of technology and our people to supercharge progress. We’re supercharging progress for everyone, everywhere – our clients, partners and their stakeholders, our people, communities, and the planet.
As an L3 Security Analyst you will be responsible for advanced-level security operations, including incident handling, threat analysis, and platform optimization. You will act as the final escalation point for security incidents, provide deep technical expertise, and contribute to proactive threat detection strategy.
Roles & Responsibilities
• Skilled in managing extensive and intricate networks, with the ability to assess how architectural design impacts attack paths, detection coverage, and telemetry visibility.
• Brings substantial hands‑on experience with continuous SIEM monitoring, validating alerts, and conducting deep investigations across identity, endpoint, network, and cloud security data, correlating signals from multiple sources to uncover real and emerging threats.
• Owns the continuous improvement of SIEM detection logic by analysing alert fidelity, false positives, missed detections, and attacker behaviour, driving measurable improvements in signal‑to‑noise ratio and detection effectiveness.
• Designs, develops, and engineers SIEM detection use cases and analytics, translating attacker techniques and observed behaviours into high‑fidelity detection logic aligned with real‑world threats.
• Proficient at identifying detection blind spots and coverage gaps by analysing incident patterns, threat intelligence, and hunting results, and proactively driving remediation through new or enhanced detection content.
• Acts as a key contributor to detection engineering efforts, providing clear, actionable requirements and feedback to ensure detection rules are scalable, maintainable, and operationally effective.
• Reviews and validates escalated SIEM incidents to confirm true‑positive cases, reconstruct attack chains, and identify opportunities for improved detection and prevention.
• Conducts proactive, hypothesis‑driven threat hunting to identify low‑signal, stealthy, and evasive attacker activity that bypasses traditional controls, feeding results directly into detection engineering pipelines.
• Leverages the MITRE ATT&CK framework to map detections, hunts, and incidents to adversary tactics and techniques, ensuring structured coverage across the attack lifecycle.
• Collects, analyses, and contextualises threat intelligence from internal investigations, vendor research, and trusted external sources, maintaining awareness of relevant threat actors, tooling, and attack trends.
• Correlates threat intelligence with internal telemetry, incidents, and hunting findings to prioritise detection development and improve investigative accuracy.
• Translates threat intelligence into actionable outcomes, including new detection logic, tuning recommendations, hunting hypotheses, and mitigation strategies.
• Supports SIEM event and incident analytics by validating detection performance, testing new rules, and ensuring detections align with evolving attacker techniques.
• Provides detailed log analysis summaries and delivers concrete recommendations to enhance detection coverage, response workflows, and preventative controls.
• Conducts advanced triage and collaborates closely with resolution teams, third parties, and designated customer contacts during complex investigations.
• Coordinates with cross‑functional teams to contribute to incident response reports, attack chain reconstruction, and post‑incident lessons‑learned reviews.
• Promotes the implementation of protection and mitigation strategies derived from threat intelligence insights, detection gaps, and post‑incident analysis.
• Produces high‑quality daily, weekly, and monthly operational, trend, and security posture reports, highlighting detection effectiveness, threat trends, and improvement areas.
• Demonstrates a self‑driven and innovative mindset, taking ownership of detection quality, threat awareness, and continuous improvement across SOC operations.
• Possesses strong knowledge of SIEM platforms, EDR technologies, IDS, detection engineering principles, and network, system, and endpoint security disciplines. • Open to working in a 24/7 operational environment.
Technical Skills:
• Expertise in SIEM/SOAR platforms.
• Strong understanding of MDR, XDR, SIEM and SOAR.
• Proficiency in Kusto Query Language (KQL) for advanced threat hunting.
• Deep knowledge of Windows, macOS, and Linux endpoint security and attack techniques (MITRE ATT&CK framework).
• Experience in forensic investigations and malware analysis.
• Strong scripting and automation skills (PowerShell, Python preferred).
• Familiarity with cloud security (Azure Defender, M365 Defender, Defender for Cloud). Soft skills • Shall have good verbal/written communication skills
• Should be willing to work in 24x7 environments • From time-to-time travel opportunities may be assigned
• Incumbent should carry continual system improvement mindset and able to demonstrate in work.
• Client facing technical analysis report and presentation skills
Education: requirement:
• Batchelor Degree in a related field (Cybersecurity, Information Security, Computer Science, Information Technology,
• Computer Engineering )or equivalent practical experience
• English Language Fluency
HCLTech is committed to protecting and securing the privacy and confidentiality of the Personal Data which it collects directly or indirectly from you when applying for a job at HCLTech either directly or through a third-party human resources agency. This notice (the “Notice”) outlines and explains how HCL Technologies Limited including its subsidiaries, local employing entities, associates, and affiliated companies [collectively referred to as “HCLTech”, “us,” “our”, or “we”] will process your Personal Data in accordance with applicable privacy legislation(s).
Candidate Data Privacy Notice | HCLTech
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search