Technical & Bus Analyst - Data & Applications

Tata Consultancy Services Limited
Stone Mountain, GA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$64,000.0 - $125,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Audit Trail User Authentication Microsoft Azure Cloud Computing Cyber Security Domain Name System (DNS) Error Codes Information Model Intrusion Detection and Prevention JSON
+8 more
Log Analysis Runbook Security Information and Event Management Syslog Data Logging Software Security Mitre Att&ck Splunk

Job description

  • Validate log types, formats, schemas, and logging methods (syslog, API, CloudTrail, JSON, custom formats).

  • Define onboarding requirements including event types, fields, timestamps, user identity, error codes,

  • and security-critical attributes.

  • Evaluate logs for completeness, reliability, and compliance with industry standard schemas.

  • Map log sources to Splunk’s Common Information Model (CIM) or equivalent normalization frameworks.

  • Log parsing, field extraction, enrichment, and timestamp normalization.

  • Development of CIM-compliant extractions for all new log sources.

  • Documentation of field dictionaries, mappings, and SIEM source type definitions.

  • Validation of proper taxonomy alignment across categories such as:

o Authentication o Authorization o Application activity o Network activity o Security events o Error/failure conditions o Administrative and privileged actions

  • Mapping application behaviors to relevant attack techniques (MITRE ATT&CK).

  • Identifying and documenting detection opportunities.

  • Authoring and implementing:

o Correlation searches o Behavioral detections o Anomaly models o High-fidelity alert logic

  • Ensuring each detection has:

o Defined data dependencies o Operational owner o Severity/priority rating o Triage response play

  • Operationalizing detections into Security Operations Runbooks, including:

o Preconditions

  • Indicators & patterns

Requirements

Must Have Technical/Functional Skills Technical Expertise

  • 5+ years working with SIEM platforms (Splunk preferred).

  • Advanced experience with CIM, ECS, or equivalent log normalization schemas.

  • Strong understanding of:

o JSON logging o Syslog/NXLog o Cloud logging architectures (AWS/GCP/Azure) o Application security telemetry o OSQuery / EDR / DNS / WAF logs

  • Proven ability to write:

o Source type definitions o Field extraction rules o Correlation logic o Detection playbooks Cybersecurity Knowledge & Competency

  • Familiarity with MITRE ATT&CK, SIGMA rules, NIST 800-53 frameworks.

  • Experience supporting SOC, IR, SIEM, Detection Engineering, or Threat Ops teams.

  • Understanding modern attack techniques, identity abuse patterns, and cloud threats.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

37 sec

Investigating anomalous operational metric logs directly and securely

Modood Alvi · WWC 2025

2:30 min

Discovering and instrumenting services using systemd process enumeration

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

Videos

See all

Related articles

See all