About this role
Duties & Responsibilities Architect and optimize SIEM platforms (e.g., Microsoft Sentinel, Splunk), including ingestion pipelines, parsing/normalization, enrichment, and correlation logic. Engineer and operate Cribl Stream and Cribl Edge for log routing, filtering, transformation, enrichment, data reduction, and destination fanout (SIEM, data lake, cold storage). Design and maintain telemetry onboarding with schema mapping, collectors/agents, connectors, API integrations, replay, and edge collection for diverse sources (endpoint, network, cloud, identity, app). Develop advanced detections and analytics (rules, queries, correlations) aligned to MITRE ATT&CK, emerging TTPs, and threat intelligence; measure detection efficacy and coverage. Lead systematic alert tuning to reduce false positives and improve signaltonoise, leveraging Cribl pipelines and SIEM analytics to standardize high-fidelity events. Build investigation assets (dashboards, hunting queries, data models) that accelerate SOC workflows and rootcause analysis across telemetry domains. Monitor ingestion health and cost (EPS/GB/day, license utilization), implement Criblbased data controls (sampling, routing, suppression) to ensure reliability and budget adherence. Perform RCA on detection gaps and pipeline failures; implement durable fixes in Cribl routes/pipelines and SIEM parsing/enrichment layers. Mentor engineers and analysts on KQL/SPL, detection engineering patterns, Cribl pipeline design, and telemetry best practices; conduct peer reviews and standards governance. Maintain documentation: data dictionaries, detection catalogs, Cribl pipeline/runbooks, ingestion maps, and metrics reporting on coverage, fidelity, MTTR, and pipeline SLOs. Requirements Basic Qualifications Solid understanding of network protocols, data protection mechanisms, and threat landscapes Hands-on experience with security systems, including firewalls, intrusion detection systems, anti-virus software, etc. Preferred Qualifications Industry-recognized certifications (e.g., CISSP, CISM, CEH) Masterβs degree in Cybersecurity or a related field
Frequently Asked Questions
Is the salary disclosed for the Lead Security Engineer (SIEM) position at staples?
The salary for this Lead Security Engineer (SIEM) role at staples is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Lead Security Engineer (SIEM) position at staples located?
This Lead Security Engineer (SIEM) role at staples is based in Chennai, Tamil Nadu, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Lead Security Engineer (SIEM) role at staples full-time or part-time?
This is listed as a Permanent position. It is posted as a Lead Security Engineer (SIEM) role at staples.
How do I apply for the Lead Security Engineer (SIEM) position at staples?
Click the "Apply Now" button on this page. You will be redirected to staples's official application portal hosted on zohorecruit where you can submit your application directly.
When was the Lead Security Engineer (SIEM) job at staples posted?
This Lead Security Engineer (SIEM) position at staples was posted on Jul 7, 2026. Apply as soon as possible β early applications are often reviewed first.