Company Name: TechDefence Labs Solutions Limited
Company Address: 9th Floor, Abhishree Adroit, Near Mansi Circle, Judges Bunglow Road, Nyay Marg, Vastrapur, Ahmedabad, Gujarat 380015
Work Location: Mumbai / Bangalore
Company Website: https://techdefencelabs.com/
Company LinkedIn Page: https://www.linkedin.com/company/techdefence/posts/?feedView=all
Designation: Senior Security Analyst
Experience: 5+ Years
JD for On-boarding Engineer.
Role overview:
Responsible for onboarding new log sources, ensuring data normalization, maintaining log quality, and supporting detection engineering initiatives.
The candidate should have strong hands-on experience in SIEM platform configuration, log parsing, data validation, and security use-case enablement.
Key responsibilities:
-
Onboard and integrate multiple security and IT data sources into the SIEM platform.
-
Support onboarding of-Network security devices (Firewalls, IDS/IPS, WAF, Proxies), EDR/XDR, IAM, Cloud platforms (AWS, Azure, GCP), Database and Infrastructure logs.
-
Configure log collection using agents, APIs, syslog, connectors, and cloud-native integrations.
-
Validate log ingestion, field extraction, parsing, and normalization.
-
Ensure logs align with the SIEM data model and taxonomy standards.
-
Perform data quality checks including completeness, timeliness, and accuracy.
-
Design and implement log parsing rules, regex extraction, and field mappings.
-
Ability to develop custom parsers and connectors.
-
Troubleshoot ingestion and parsing issues across diverse data formats.
-
Work closely with SOC analysts, detection engineers, platform administrators, and customers.
-
Provide onboarding guidance and log requirement recommendations.
-
Support audit and compliance log validation activities.
Required technical skill sets:
-
Hands-on experience with at least one SIEM platform.
-
Experience onboarding logs from AWS CloudTrail, GuardDuty, VPC Flow Logs, Azure Monitor, Entra ID logs, SaaS applications via APIs.
-
Strong understanding of: Syslog protocols REST APIs, JSON, XML, CSV log formats, Regex and log parsing techniques, Event normalization and enrichment.
-
Working knowledge of Python / Shell scripting.
-
Experience with Linux/Unix and Windows logging mechanisms.
-
Knowledge of network protocols and security telemetry.
-
Understanding of SOC operations and incident detection lifecycle and MITRE framework.