Skip to main content
Posted 30 August, 2026

SIEM Architect

Tata Consultancy Services
600001, TN, IN Full Time
Reference: c06203ca37a6c11c

Job Description

\n

SIEM Architect

\n


\n

Required Technical Skill Set**

\n

Microsoft Sentinel SIEM Architect with strong expertise in Azure security technologies.

\n


\n

Desired Experience Range**

\n

10-15 YRS

\n


\n

Location of Requirement

\n

Chennai

\n


\n

Desired Competencies (Technical/Behavioral Competency)

\n

Must-Have

\n

We are seeking an experienced Microsoft Sentinel SIEM Architect with strong expertise in Azure security technologies, AI-driven security (Azure OpenAI), and Microsoft Security Copilot. The ideal candidate will design, implement, and optimize modern cloud-native SIEM/SOAR solutions, while leveraging AI and automation to enhance threat detection, response, and SOC efficiency.

\n


\n

Good-to-Have

\n
    \n
  • Use Azure OpenAI for threat analysis, summarization, KQL/playbook generation
  • \n
  • Leverage Security Copilot for investigation and response
  • \n
  • Build AI workflows using prompt engineering & automation
  • \n
\n


\n


\n

Responsibility of / Expectations from the Role

\n

1

\n

Design and implement end-to-end Sentinel architectures. Define ingestion, normalization (ASIM), and retention strategies. Architect multi-region & multi-tenant solutions.

\n

2

\n

Develop HLD & LLD documentation, Integrate Azure, M365, Defender, on-prem (Syslog/CEF), AWS, GCP.

\n

3

\n

Configure AMA, Event Hub, APIs, Logic Apps, Implement log filtering, transformation, enrichment.

\n

4

\n

Develop HLD & LLD documentation, Integrate Azure, M365, Defender, on-prem (Syslog/CEF), AWS, GCP

\n

5

\n

Custom Connector , Application log Source onboarding, Develop KQL-based analytics rules, Implement Fusion (ML) and NRT detections, Map to MITRE ATT&CK, Tune alerts and reduce false positives.

\n

6

\n

Build Logic Apps playbooks, Automate triage, containment (IP/user actions), ticketing integration, Define automation lifecycle rules.

\n

7

\n

Design L1/L2/L3 SOC workflows, Define severity, escalation, classification, Support threat hunting & incident response.

\n

8

\n

Implement RBAC, PIM, Ensure ISO 27001, NIST, CIS compliance, Align logging with regulatory requirements.

\n

9

\n

Optimize ingestion filtering, Manage retention (hot/archive), Monitor cost & performance efficiency.

\n

10

\n

Preferred Certifications

\n
    \n
  • SC-100 – Microsoft Cybersecurity Architect
  • \n
  • SC-200 – Security Operations Analyst
  • \n
  • AZ-500 – Azure Security Engineer
  • \n
  • Azure AI / OpenAI certifications (preferred)
  • \n
\n

11

\n

Key Competencies

\n
    \n
  • Strong analytical & problem-solving skills
  • \n
  • Enterprise-scale architecture design
  • \n
  • AI-driven SOC transformation expertise
  • \n
  • Stakeholder & SOC communication skills
  • \n
\n

Sign up for Job Alerts