IT Security Engineer / Architect Lead
Chennai, INFull-timePosted Aug 6, 2026
What Drives Success
The Lead Architect – SIEM, SOAR, UEBA, Security Analytics is responsible for defining and executing the enterprise vision for Security Information and Event Management (SIEM), Security Analytics, Detection Engineering, Threat Hunting, UEBA and SOAR Automation. This role will drive the modernization of the Security Operations Center through AI-driven analytics, automation-first operations, and advanced threat detection strategies.
Key Responsibilities
SIEM Strategy & Architecture
- Own enterprise SIEM architecture and technology roadmap.
- Define SIEM standards, governance, onboarding strategy, and data architecture.
- Lead migration, optimization, and modernization initiatives across SIEM platforms.
- Establish scalable security monitoring frameworks across on-premises, cloud, SaaS, and OT environments.
Detection Engineering
- Build and govern detection engineering programs aligned to MITRE ATT&CK.
- Design and maintain high-fidelity correlation rules and behavioral analytics.
- Implement Detection-as-Code methodologies using CI/CD practices.
- Reduce false positives through continuous tuning and threat-informed detection.
SOAR & AI Security Operations
- Define SOAR architecture and automation strategy.
- Implement automated incident investigation and containment workflows.
- Leverage AI and machine learning to improve triage and threat detection efficiency.
- Enable machine-speed response for critical security incidents.
Threat Hunting & Analytics
- Lead proactive threat hunting capabilities.
- Develop hunt methodologies for:
- Identity attacks
- Insider threats
- Cloud attacks
- Ransomware precursors
- AI-assisted attacks
- Convert hunt findings into operational detections.
Leadership & Governance
- Mentor SIEM Engineers, Detection Engineers, and SOC Analysts.
- Conduct architecture reviews, tabletop exercises, and cyber readiness assessments.
- Partner with Incident Response, Cloud Security, AppSec, and Data Protection teams.
What We Are Looking For
- 12-15+ years of cybersecurity experience.
- 8+ years in SIEM Engineering, Detection Engineering, SOC Engineering, or Security Architecture.
- Experience with enterprise-scale SOC transformation programs.
- Strong expertise in cloud-native security monitoring.
Technical Skills
- Splunk Enterprise Security
- Microsoft Sentinel
- Cortex XSIAM
- Elastic Security
- MITRE ATT&CK
- SOAR Platforms
- Threat Intelligence
- UEBA
- EDR/XDR
- Cloud Security Monitoring
- AI Security & Security Copilot