Track Lead - Security Analysis, SIEM

Apply Now ↗
📍 Lucknow, India

About this role

Job Summary

Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.

Key Responsibilities

Conduct hypothesis-based and IOC-driven threat hunting across: o Endpoint (EDR/XDR) o SIEM / Log Management platforms o Network telemetry (NDR) o Identity logs (AD / Entra ID) o Cloud platforms (Azure, AWS, M365) • Identify stealthy and advanced threats, including: o Living off the Land (LotL) techniques o Advanced Persistent Threats (APTs) o Lateral movement and privilege escalation o Insider threat indicators • Develop and execute MITRE ATT&CK;–aligned hunting hypotheses • Convert hunting findings into: o Security incidents o New detection rules (SIEM / EDR / XDR) o Change or service requests (misconfigurations, logging gaps) • Collaborate with SOC, Incident Response, and Threat Intelligence teams • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated)

Skill Requirements

Technical Skills • Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM) • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex) • Proficiency in KQL / SPL / advanced hunting queries • Deep understanding of MITRE ATT&CK; techniques and TTPs • Strong OS knowledge: Windows, Linux, macOS • Basic scripting skills (PowerShell / Python preferred) • Cloud security exposure (Azure, AWS, M365 Defender) Experience & Soft Skills • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting • Strong analytical and investigative mindset • Client facing reporting and presentation skills • Willingness to work in 24×7 SOC environments

Other Requirements

Role Overview Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity. Key Responsibilities • Conduct hypothesis-based and IOC-driven threat hunting across: o Endpoint (EDR/XDR) o SIEM / Log Management platforms o Network telemetry (NDR) o Identity logs (AD / Entra ID) o Cloud platforms (Azure, AWS, M365) • Identify stealthy and advanced threats, including: o Living off the Land (LotL) techniques o Advanced Persistent Threats (APTs) o Lateral movement and privilege escalation o Insider threat indicators • Develop and execute MITRE ATT&CK;–aligned hunting hypotheses • Convert hunting findings into: o Security incidents o New detection rules (SIEM / EDR / XDR) o Change or service requests (misconfigurations, logging gaps) • Collaborate with SOC, Incident Response, and Threat Intelligence teams • Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated) Technical Skills • Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM) • Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex) • Proficiency in KQL / SPL / advanced hunting queries • Deep understanding of MITRE ATT&CK; techniques and TTPs • Strong OS knowledge: Windows, Linux, macOS • Basic scripting skills (PowerShell / Python preferred) • Cloud security exposure (Azure, AWS, M365 Defender) Experience & Soft Skills • 6+ years in SOC / Threat Detection, with 2+ years in threat hunting • Strong analytical and investigative mindset • Client facing reporting and presentation skills • Willingness to work in 24×7 SOC environments Key Sourcing Information : NA Interviewer 1 SAP ID : 51493488 Job Description : Role Overview\\\\r\\\\nResponsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.\\\\r\\\\n\\\\r\\\\nKey Responsibilities\\\\r\\\\n• Conduct hypothesis-based and IOC-driven threat hunting across: \\\\r\\\\no Endpoint (EDR/XDR)\\\\r\\\\no SIEM / Log Management platforms\\\\r\\\\no Network telemetry (NDR)\\\\r\\\\no Identity logs (AD / Entra ID)\\\\r\\\\no Cloud platforms (Azure, AWS, M365)\\\\r\\\\n• Identify stealthy and advanced threats, including: \\\\r\\\\no Living off the Land (LotL) techniques\\\\r\\\\no Advanced Persistent Threats (APTs)\\\\r\\\\no Lateral movement and privilege escalation\\\\r\\\\no Insider threat indicators\\\\r\\\\n• Develop and execute MITRE ATT&CK;–aligned hunting hypotheses\\\\r\\\\n• Convert hunting findings into: \\\\r\\\\no Security incidents\\\\r\\\\no New detection rules (SIEM / EDR / XDR)\\\\r\\\\no Change or service requests (misconfigurations, logging gaps)\\\\r\\\\n• Collaborate with SOC, Incident Response, and Threat Intelligence teams\\\\r\\\\n• Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated) \\\\r\\\\nTechnical Skills\\\\r\\\\n• Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM)\\\\r\\\\n• Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex)\\\\r\\\\n• Proficiency in KQL / SPL / advanced hunting queries\\\\r\\\\n• Deep understanding of MITRE ATT&CK; techniques and TTPs\\\\r\\\\n• Strong OS knowledge: Windows, Linux, macOS\\\\r\\\\n• Basic scripting skills (PowerShell / Python preferred)\\\\r\\\\n• Cloud security exposure (Azure, AWS, M365 Defender) \\\\r\\\\nExperience & Soft Skills\\\\r\\\\n• 6+ years in SOC / Threat Detection,

Frequently Asked Questions

Is the salary disclosed for the Track Lead - Security Analysis, SIEM position at HCLTech?
The salary for this Track Lead - Security Analysis, SIEM role at HCLTech is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Track Lead - Security Analysis, SIEM position at HCLTech located?
This Track Lead - Security Analysis, SIEM role at HCLTech is based in Lucknow, India. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
How do I apply for the Track Lead - Security Analysis, SIEM position at HCLTech?
Click the "Apply Now" button on this page. You will be redirected to HCLTech's official application portal hosted on successfactors where you can submit your application directly.
When was the Track Lead - Security Analysis, SIEM job at HCLTech posted?
This Track Lead - Security Analysis, SIEM position at HCLTech was posted on Aug 28, 2026. Apply as soon as possible — early applications are often reviewed first.
Track Lead - Security Analysis, SIEM
HCLTech
Apply for this role ↗

You'll be redirected to HCLTech's official application page on successfactors.