> Markdown version of [/jobs/ext/1240054-technical-bus-analyst-data-applications](https://www.wearedevelopers.com/jobs/ext/1240054-technical-bus-analyst-data-applications). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Technical & Bus Analyst - Data & Applications - **Company:** Tata Consultancy Services Limited - **Location:** Stone Mountain, GA, United States - **Experience:** Expert - **Salary:** $64,000.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Audit Trail, User Authentication, Microsoft Azure, Cloud Computing, Cyber Security, Domain Name System (DNS), Error Codes, Information Model, Intrusion Detection and Prevention, JSON, Log Analysis, Runbook, Security Information and Event Management, Syslog, Data Logging, Software Security, Mitre Att&ck, Splunk - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6acc3563439d6ab4 ## About the Role Must Have Technical/Functional Skills Technical Expertise * 5+ years working with SIEM platforms (Splunk preferred). * Advanced experience with CIM, ECS, or equivalent log normalization schemas. * Strong understanding of: o JSON logging o Syslog/NXLog o Cloud logging architectures (AWS/GCP/Azure) o Application security telemetry o OSQuery / EDR / DNS / WAF logs * Proven ability to write: o Source type definitions o Field extraction rules o Correlation logic o Detection playbooks Cybersecurity Knowledge & Competency * Familiarity with MITRE ATT&CK, SIGMA rules, NIST 800-53 frameworks. * Experience supporting SOC, IR, SIEM, Detection Engineering, or Threat Ops teams. * Understanding modern attack techniques, identity abuse patterns, and cloud threats. ## Description * Validate log types, formats, schemas, and logging methods (syslog, API, CloudTrail, JSON, custom formats). * Define onboarding requirements including event types, fields, timestamps, user identity, error codes, * and security-critical attributes. * Evaluate logs for completeness, reliability, and compliance with industry standard schemas. * Map log sources to Splunk's Common Information Model (CIM) or equivalent normalization frameworks. * Log parsing, field extraction, enrichment, and timestamp normalization. * Development of CIM-compliant extractions for all new log sources. * Documentation of field dictionaries, mappings, and SIEM source type definitions. * Validation of proper taxonomy alignment across categories such as: o Authentication o Authorization o Application activity o Network activity o Security events o Error/failure conditions o Administrative and privileged actions * Mapping application behaviors to relevant attack techniques (MITRE ATT&CK). * Identifying and documenting detection opportunities. * Authoring and implementing: o Correlation searches o Behavioral detections o Anomaly models o High-fidelity alert logic * Ensuring each detection has: o Defined data dependencies o Operational owner o Severity/priority rating o Triage response play * Operationalizing detections into Security Operations Runbooks, including: o Preconditions * Indicators & patterns ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top Big Data Technologies That You Need to Know](https://www.wearedevelopers.com/magazine/108-top-big-data-technologies-that-you-need-to-know) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)