L2 SIEM Administrator - LogRhythm at TapRootz · Pune · 3.5 - 8 years · ₹15L - ₹25L / yr · Raised funding · Posted 13 Jan 2025

Job Title: L2 SIEM Administrator - LogRhythm
Location:
Pune – Customer Site (Magarpatta)
Job Summary:
We are seeking an experienced and proactive L2 SIEM Administrator with expertise in LogRhythm to manage, maintain, and optimize our Security Information and Event Management (SIEM) infrastructure.
The ideal candidate will develop use case frameworks, implement SIEM rules, and ensure efficient log management and threat detection.
Key Responsibilities:
LogRhythm Administration:
Manage and maintain the LogRhythm SIEM platform for optimal performance.
Develop, implement, and fine-tune use case frameworks and detection rules to enhance threat detection.
Incident Analysis:
Investigate security alerts and logs to identify and respond to threats.
Escalate unresolved issues to higher-level teams or external stakeholders.
Log Management:
Onboard and configure log sources, ensuring accurate data ingestion and normalization.
Validate log integrity across network and endpoint sources.
Optimization and Troubleshooting:
Resolve technical issues and optimize system performance.
Monitor and maintain dashboards and reporting tools for actionable insights.
Qualifications:
Proven expertise with LogRhythm, including creating and managing use case frameworks and detection rules.
3+ years of experience in SIEM administration.
Strong understanding of security logs, event correlation, and incident analysis.
Familiarity with scripting (Python, PowerShell) and security frameworks (e.g., MITRE ATT&CK).
Relevant certifications (e.g., LogRhythm Certified Professional (LRCP)) are a plus.

About TapRootz
About
Similar jobs (10)
Job Summary:
We are looking for an experienced OpenText ArcSight SIEM / SOAR / UBA L2-L3 Engineer to manage and support security platforms in SOC/MSSP environment. The role involves day-to-day administration, troubleshooting, configuration and optimization of ArcSight platforms.
Key Responsibilities
- Administer and monitor OpenText ArcSight ESM/SIEM, SmartConnectors, SOAR and UBA/ArcSight Intelligence.
- Manage SIEM rules, filters, Active Lists, dashboards, reports and correlation use cases.
- Monitor EPS, event flow, connector health, system performance and log ingestion.
- Troubleshoot event collection, parsing, correlation and integration issues.
- Configure and troubleshoot ArcSight SmartConnectors and log sources.
- Manage and troubleshoot SOAR playbooks, integrations and automated workflows.
- Support UBA/Intelligence data ingestion, analytics and integration with SIEM.
- Perform L2/L3 troubleshooting, RCA and resolution of platform-related incidents.
- Support upgrades, patches, configuration changes and platform optimization.
- Coordinate with SOC, infrastructure, customer and OEM/OpenText support teams.
- Maintain technical documentation, incident records and RCA reports.
Required Skills
- 3–6 years of hands-on experience with OpenText ArcSight SIEM/ESM.
- Strong experience in ArcSight administration and troubleshooting.
- Hands-on experience with SmartConnectors, EPS, correlation rules, Active Lists and event flow.
- Working experience with ArcSight SOAR and UBA/ArcSight Intelligence.
- Good knowledge of Linux/Unix and networking fundamentals.
- Understanding of Syslog, CEF, TCP/IP, SSL/TLS and REST APIs.
- Strong analytical, troubleshooting and problem-solving skills.
- Experience in SOC/MSSP or managed security services environment preferred.
- OpenText/ArcSight certification will be an added advantage.
Candidate Profile
The candidate should be hands-on, technically strong and capable of independently handling L2/L3 production issues, platform administration, troubleshooting and escalations in a security operations environment.
The Security Analyst assists the Data Security team to help ensure the security of the company and its clients. Looking for immediate joiners.
KEY RESPONSIBILITIES
All employees are expected to use good business judgment and appropriate discretion and decision making while performing responsibilities of the position, and to incorporate EVA’s Core Beliefs in their daily work.
- Performs daily health checks as documented by the IT Security team.
- Supports the Security team by documenting and performing support tasks.
- Participates in change management, incident management, audit and business continuity processes.
- Plans and implements security policies and procedures to protect computer systems, networks and data from unauthorized access.
- Participates in internal and external compliance (SOC 2) audits.
- Recommends security enhancements.
Job specifics:
- Familiarity with standard security concepts, practices and procedures.
- Knowledge of Windows operating systems.
- Strong Documentation, communication skills and attention to detail.
- Able to work independently and as a part of a team to deliver completed projects on-time.
- Identifies ways to continuously improve own and/or company performance.
- Knowledge of security toolsets
- Knowledge of compliance activities (GDPR, SOC 2, ISO:27001).
- Knowledge of database security.
- Knowledge of SIEM technology and security event correlation and monitoring.
- Experience with AWS.
- Proficient with computer software including Salesforce
EDUCATION & EXPERIENCE
- Bachelor’s Degree in computer science, mathematics, Information Systems or equivalent experience preferred.
- Minimum of 3 years of hands-on IT Security & Audit experience.
- Professional IT Security Certifications are strongly preferred, such as Security+, CISSP, CISM, CISA, GSEC, etc.
Job Description – Tines SOAR Engineer
Job Title: Tines SOAR Engineer
Experience: 6+ Years
Employment Type: Contract
Job Location: India – Hybrid/Remote
Company: Prama.ai
About the Role
Prama.ai is looking for an experienced Tines SOAR Engineer to design, develop, and maintain security automation workflows for enterprise SOC environments. The ideal candidate should have strong hands-on experience with Tines SOAR, security operations, incident response, API integrations, and automation.
Key Responsibilities
- Design, develop, and maintain automation workflows (Tines Stories).
- Build and enhance security playbooks for incident response and alert handling.
- Develop integrations between Tines and SIEM, EDR/XDR, IAM, ITSM, and other security tools.
- Implement integrations using REST APIs, Webhooks, JSON, and OAuth.
- Automate repetitive SOC and security operations to improve incident response efficiency.
- Troubleshoot, monitor, and optimize Tines automation workflows.
- Collaborate with SOC, Security, Infrastructure, and IT teams.
- Support security automation use cases across enterprise environments.
Required Skills
- 6+ years of IT/Security experience with strong hands-on experience in Tines SOAR.
- Hands-on experience developing Tines Stories, Actions, Event Transformations, and API integrations.
- Strong understanding of SOC, Incident Response, Security Operations, and Security Automation.
- Strong knowledge of REST APIs, JSON, Webhooks, and OAuth.
- Experience with at least one SIEM:
- Microsoft Sentinel
- Splunk
- IBM QRadar
- Google Chronicle
- Experience with at least one EDR/XDR:
- Microsoft Defender
- CrowdStrike
- SentinelOne
- Cortex XDR
- Scripting experience in Python, JavaScript, or PowerShell.
- Experience with ServiceNow or Jira.
- Working knowledge of Windows/Linux environments.
- Good understanding of TCP/IP, DNS, HTTP/HTTPS.
- Knowledge of Active Directory, Entra ID, or Okta.
Preferred Skills
- Experience working with Banking/BFSI clients.
- Knowledge of Microsoft Security Stack.
- Understanding of Threat Intelligence and MITRE ATT&CK.
- Exposure to AWS or Azure Security.
- Experience with enterprise SOC automation and security integrations.
Preferred Certifications
- Tines Certification
- Microsoft SC-200
- CompTIA Security+ / CySA+
- Microsoft AZ-500
This role will be permanent with NAM info and deploy to client location Chennai.
Work Mode: WORK FROM OFFICE
Offer salary can offer on a decent hike
Role Descriptions:
Exp Range: 6-10 years
Primary Competency : Terraform, Hashi Sentinel (IaC/PaC), Kubernetes (GKE/EKS)
City Locations: Bengaluru or Chennai
Key Responsibilities*
Experience Required: 6-10
Role Descriptions:
Security Monitoring & Incident Response
Investigate and analyze security alerts escalated by L1 SOC analysts.
Perform triage, containment, eradication, and recovery activities for security incidents.
1. Perform in-depth analysis of security alerts escalated from L1
2. Investigate suspicious activities using SIEM, EDR, and threat intelligence tools
3. Correlate events across multiple log sources (firewalls, endpoints, IAM, cloud logs)
4. Validate true positives and recommend reducing false positives
5. Lead triage and response for medium to high severity incidents
6. Coordinate with IT, network, and application teams during incidents and support deep investigations when required
7. Conduct proactive threat hunting based on TTPs (e.g., MITRE ATT&CK)
8. Fine-tuning and optimize SIEM use cases to reduce false positives
9. Develop new correlation rules and detection logic
10. Document incidents, findings, and response actions
11. Prepare weekly , monthly reports for SOC leadership and stakeholders
Desire candidate
- Candidate should have valid PF.
About the role
You will create and validate the detection content that protects our customers: IDPS signatures, application control rules, and DLP rules. This is a hands-on role in our security lab, where you will generate real attack traffic, research vulnerabilities and applications, and make sure every rule is accurate, effective, and ready for production.
What you'll do
Write security rules
- Write IDPS signatures for exploits, malware, command-and-control traffic, and network attacks, with the right severity, action (alert / block / reject), and protocol scope
- Build application control rules to identify and control social media, streaming, file sharing, remote access, unsanctioned SaaS, and AI tools
- Create DLP rules to detect sensitive data (personal and financial data, confidential documents, source code) across web, email, and file transfer channels
Test and validate
- Set up test scenarios in our lab and generate traffic using browsers, command-line tools, packet captures, and safe proof-of-concept exploits
- Confirm that each rule triggers and that logs show the correct rule, severity, action, and source
- Test against normal everyday traffic to find and fix false positives before rules ship
- Build and maintain a repeatable test set so rules keep working after product updates
Research and document
- Track new CVEs, exploit techniques, and emerging applications, and turn them into working detections
- Study public r
- Study public rulesets to learn coverage patterns and find gaps in our own
- Write a short validation note for each batch: what it detects, how it was tested, and what it doesn't cover
What we're looking for
- 2-5 years of hands-on experience writing detection rules or signatures with Snort, Suricata, Zeek, YARA, Sigma, or similar
- Strong networking fundamentals: TCP/IP, HTTP/HTTPS, DNS, TLS, and packet analysis with Wireshark or pcap tools
- Experience testing rules with PoC exploits and tuning them to reduce false positives
- Exposure to CVE and vulnerability research, with the ability to read advisories and turn them into detections
- Working knowledge of Python or Bash for test automation, and comfort with Linux
- Clear written communication, since you'll document what each rule covers and what it doesn't
Good to have
- Experience with deep packet inspection, application identification (nDPI or similar), or DLP regex and pattern work
- Background at a network security vendor (firewall, IPS, NGFW, secure web gateway)
- Public work such as GitHub rules, blog posts, CVE credits, or CTF participation
This role is not
A SOC monitoring, alert triage, or pure penetration testing role. We are looking for people who write and test detection rules.
Mandatory Skills: L2 Production Support, Event Management / Mission Control, Incident Management, Linux, Linux, observability, and batch monitoring
Primary Skills:
- L2 Production Support, Event Management / Mission Control, ServiceNow, Production Monitoring, Splunk / AppDynamics / ThousandEyes
At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.
Learn more at www.shipthis.co
Role Overview
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
What You’ll be Doing
Security Operations
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
- Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
- Track security issues and corrective actions through closure.
Vulnerability Management
- Run and review application and infrastructure vulnerability scans.
- Maintain a vulnerability register and coordinate remediation with engineering teams.
- Support VAPT and penetration-testing exercises and validate closure of findings.
- Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
- Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
- Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain device inventory and monitor endpoint compliance.
- Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
- Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
- Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
- Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
- Automate repetitive deployment, infrastructure, security, and compliance tasks.
- Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
- Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Required Fundamentals
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Desired Qualifications
- 1–2 years of experience with strong fundamentals are welcome.
- Basic scripting knowledge in Python, Bash, or similar.
- Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates:
- Who can join immediately
- Female candidates returning to work after a career break are strongly encouraged.
We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.
Job Synopsys
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
Primary Skills: Linux Administration, Production Support
Secondary Skills: Oracle SQL, Splunk, Grafana, AppDynamics, Cloud (OCP/AWS/Azure/GCP), Incident Management, AI/Automation.
About the role
We’re hiring an IT Systems Administrator for an NBFC to secure endpoints, SaaS, and networks across ~50 branches, ~250+ field staff, and ~50+ office users.
This is primarily an IT Admin + Security role, with secondary exposure to AWS cloud ops + light DevOps + basic DB access management.
If you’re an IT Admin aiming to break into AWS Cloud Ops + DevOps, this role is a strong next step — you’ll own core IT/security and get hands-on exposure to cloud operations and deployments.
Key responsibilities (Primary: IT Admin + Security)
- Manage endpoint security for laptops and mobiles (policies, patching, encryption, antivirus/EDR); drive MDM implementation now/future (e.g., Intune/Jamf).
- Administer Google Workspace (Gmail/Drive/Calendar): users, groups, permissions, SSO, MFA, sharing controls.
- Own joiner–mover–leaver lifecycle: provisioning/deprovisioning, access controls, periodic access reviews.
- Secure branch connectivity: VPN, internal Wi-Fi, internet usage controls; coordinate troubleshooting and standardization across branches.
- Manage HO security stack: firewall operations, rule changes with change control, monitoring/log review (basic but consistent).
- Secure SaaS tools (CRM/HRMS/comms like Slack/Zoom): role-based access, MFA enforcement, offboarding, integration/OAuth controls.
- Maintain IT asset inventory: procurement coordination, issuance/return, audits, warranty/AMC, license renewals; remote lock/wipe for lost devices.
- Handle security incidents: phishing, account compromise, device loss/theft — contain, investigate, recover, and prevent recurrence.
- Run backups and basic DR testing; maintain SOPs/documentation and train staff on cyber hygiene.
- Provide hands-on user support: laptop builds, software installs, Outlook/Excel issues, VPN/Wi-Fi troubleshooting, escalations and vendor coordination.
Secondary responsibilities (AWS + DevOps + DB ops support)
- Support AWS administration: IAM users/roles/policies, MFA, access key hygiene, basic log review (e.g., CloudTrail).
- Manage AWS access controls: security groups/firewall rules, IP allowlists/whitelisting (admin tools, databases, vendor access).
- Assist engineering with DevOps operations:
- CI/CD support (deployment coordination, rollbacks, environment configuration)
- Secrets/credentials management and rotation (no shared creds)
- DNS + SSL/TLS certificates, basic monitoring/alerting coordination
- Bonus: Docker/Kubernetes and Terraform exposure
- Basic database operations (admin-lite):
- DB user creation, roles/permissions, least-privilege access
- IP allowlisting/whitelisting for DB access via VPN/approved sources
- Backup/restore verification coordination and basic monitoring signals (connections/storage)
Requirements
- 3+ years in IT security / systems administration (BFSI or branch-heavy org preferred).
- Hands-on with Google Workspace or Microsoft 365 administration.
- Must have hands-on experience leading or executing an email suite migration (e.g., Google Workspace ↔ Microsoft 365), including mailbox migration, DNS cutover, MX/SPF/DKIM/DMARC reconfiguration, and user transition management.
- Strong endpoint/security fundamentals: encryption, patching, AV/EDR, remote support, device compliance.
- Comfortable with networks: VPN/Wi-Fi/LAN troubleshooting; firewall basics and change discipline.
- Strong operational discipline: asset tracking, vendor management, documentation, ticketing, user communication.
- Practical AWS familiarity (IAM, access controls, logging) and ability to support DevOps workflows.
Nice to have
- Experience implementing MDM at scale (Intune/Jamf/SureMDM).
- Exposure to SOC2 / ISO27001 evidence, controls, and audit workflows.
- Scripting for automation (PowerShell/Bash/Python).
- Familiarity with managed databases and secure access patterns.










