Sr Subject Matter Expert (Support&Ops)

Apply Now ↗
📍 Pune, India

About this role

Job Summary

Years of Experience

  • 12+ years of experience in SIEM engineering, Splunk administration, security analytics, detection engineering, and enterprise log-management environments.

General Description

  • Serve as the L3 SME for Customer’s Splunk Cloud managed service, responsible for advanced troubleshooting, engineering, optimization, and technical governance. 
  • Lead complex data onboarding, detection-content engineering, advanced dashboarding, alert tuning, performance optimization, and RCA support. 
  • Provide technical oversight to L2 engineers and collaborate with Customer, SOC/MSSP, IAM, PAM, AppSec, DevOps, network, cloud, and application teams. 

 

 

Key Responsibilities

Technical Requirements

  • Hands-on experience with Splunk Enterprise and/or Splunk Cloud in enterprise environments. 
  • Experience with SPL searches, dashboards, reports, alerts, field extractions, sourcetypes, indexes, and knowledge objects. 
  • Experience in log-source onboarding, ingestion validation, parsing, field mapping, data-quality checks, and pipeline troubleshooting. 
  • Knowledge of SIEM operations, security monitoring, incident investigation, RCA evidence, and operational reporting. 
  • Experience integrating Splunk with IAM, PAM, SSO, EDR, cloud, network-security, application, and infrastructure data sources. 
  • Experience with ServiceNow/Jira, incident, request, change, and problem management processes. 
  • Ability to maintain use-case catalogues, data-source inventories, dashboard inventories, runbooks, and service metrics. 
  • Advanced SPL development and optimization, data models, accelerated searches, correlation searches, macros, lookups, and enterprise-scale dashboard design. 
  • Strong experience in detection engineering, MITRE ATT&CK mapping, use-case lifecycle management, tuning methodology, and security-content governance. 
  • Experience troubleshooting complex ingestion architecture, heavy forwarders, universal forwarders, HEC, APIs, cloud integrations, and data-routing issues. 
  • Knowledge of Splunk Cloud architecture, search performance, ingestion forecasting, retention, index strategy, and cost/license optimization. 
  • Ability to lead RCA, problem management, technical reviews, platform upgrades, automation, and continuous-improvement initiatives. 
  • Experience with Python, REST APIs, Git, CI/CD, and automation of Splunk administration and content deployment. 

Soft Skills

  • Excellent communication and presentation skills.
  • Strong problem-solving and critical thinking skills.
  • Exceptional project management and organizational abilities.
  • Team collaboration and leadership skills.
  • Client-focused approach with a commitment to delivering exceptional customer service.

Certifications (Good to have)

Good to have relevant certificates like (any of the below):

  • Splunk Enterprise Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Security Certified Admin. 
  • CISSP, GCIA, GCIH, CySA+, or equivalent security certification is preferred.

Educational Qualifications

  • University degree in IT or/and IT Security.
  • Bachelor’s degree in computer science/ IT or any relevant fields.

 

Skill Requirements

Technical Requirements

  • Hands-on experience with Splunk Enterprise and/or Splunk Cloud in enterprise environments. 
  • Experience with SPL searches, dashboards, reports, alerts, field extractions, sourcetypes, indexes, and knowledge objects. 
  • Experience in log-source onboarding, ingestion validation, parsing, field mapping, data-quality checks, and pipeline troubleshooting. 
  • Knowledge of SIEM operations, security monitoring, incident investigation, RCA evidence, and operational reporting. 
  • Experience integrating Splunk with IAM, PAM, SSO, EDR, cloud, network-security, application, and infrastructure data sources. 
  • Experience with ServiceNow/Jira, incident, request, change, and problem management processes. 
  • Ability to maintain use-case catalogues, data-source inventories, dashboard inventories, runbooks, and service metrics. 
  • Advanced SPL development and optimization, data models, accelerated searches, correlation searches, macros, lookups, and enterprise-scale dashboard design. 
  • Strong experience in detection engineering, MITRE ATT&CK mapping, use-case lifecycle management, tuning methodology, and security-content governance. 
  • Experience troubleshooting complex ingestion architecture, heavy forwarders, universal forwarders, HEC, APIs, cloud integrations, and data-routing issues. 
  • Knowledge of Splunk Cloud architecture, search performance, ingestion forecasting, retention, index strategy, and cost/license optimization. 
  • Ability to lead RCA, problem management, technical reviews, platform upgrades, automation, and continuous-improvement initiatives. 
  • Experience with Python, REST APIs, Git, CI/CD, and automation of Splunk administration and content deployment. 

Soft Skills

  • Excellent communication and presentation skills.
  • Strong problem-solving and critical thinking skills.
  • Exceptional project management and organizational abilities.
  • Team collaboration and leadership skills.
  • Client-focused approach with a commitment to delivering exceptional customer service.

Certifications (Good to have)

Good to have relevant certificates like (any of the below):

  • Splunk Enterprise Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Security Certified Admin. 
  • CISSP, GCIA, GCIH, CySA+, or equivalent security certification is preferred.

Educational Qualifications

  • University degree in IT or/and IT Security.
  • Bachelor’s degree in computer science/ IT or any relevant fields.

 

Other Requirements

Frequently Asked Questions

Is the salary disclosed for the Sr Subject Matter Expert (Support&Ops) position at HCLTech?
The salary for this Sr Subject Matter Expert (Support&Ops) role at HCLTech is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Sr Subject Matter Expert (Support&Ops) position at HCLTech located?
This Sr Subject Matter Expert (Support&Ops) role at HCLTech is based in Pune, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
How do I apply for the Sr Subject Matter Expert (Support&Ops) position at HCLTech?
Click the "Apply Now" button on this page. You will be redirected to HCLTech's official application portal hosted on successfactors where you can submit your application directly.
When was the Sr Subject Matter Expert (Support&Ops) job at HCLTech posted?
This Sr Subject Matter Expert (Support&Ops) position at HCLTech was posted on Sep 7, 2026. Apply as soon as possible — early applications are often reviewed first.
Sr Subject Matter Expert (Support&Ops)
HCLTech
Apply for this role ↗

You'll be redirected to HCLTech's official application page on successfactors.