Technical & Bus Analyst - Data & Applications

Tata Consultancy Services Limited
Durham, NC, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$64,000.0 - $110,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services User Authentication Microsoft Azure Cloud Computing Cyber Security DevOps Domain Name System (DNS) Error Codes Information Model Intrusion Detection and Prevention JSON Log Analysis
+7 more
Runbook Security Information and Event Management Syslog Data Logging Software Security Mitre Att&ck Splunk

Job description

  • Validate log types, formats, schemas, and logging methods (syslog, API, CloudTrail, JSON, custom formats).

  • Define onboarding requirements including event types, fields, timestamps, user identity, error codes,

  • and security-critical attributes.

  • Evaluate logs for completeness, reliability, and compliance with industry standard schemas.

  • Map log sources to Splunk’s Common Information Model (CIM) or equivalent normalization frameworks.

  • Log parsing, field extraction, enrichment, and timestamp normalization.

  • Development of CIM-compliant extractions for all new log sources.

  • Documentation of field dictionaries, mappings, and SIEM source type definitions.

  • Validation of proper taxonomy alignment across categories such as:

o Authentication o Authorization o Application activity o Network activity o Security events o Error/failure conditions o Administrative and privileged actions

  • Mapping application behaviors to relevant attack techniques (MITRE ATT&CK).

  • Identifying and documenting detection opportunities.

  • Authoring and implementing:

o Correlation searches o Behavioral detections o Anomaly models o High-fidelity alert logic

  • Ensuring each detection has:

o Defined data dependencies o Operational owner o Severity/priority rating o Triage response play

  • Operationalizing detections into Security Operations Runbooks, including:

o Preconditions

  • Indicators & patterns

Requirements

Must Have Technical/Functional Skills Technical Expertise

  • 5+ years working with SIEM platforms (Splunk preferred).

  • Advanced experience with CIM, ECS, or equivalent log normalization schemas.

  • Strong understanding of:

o JSON logging o Syslog/NXLog o Cloud logging architectures (AWS/GCP/Azure) o Application security telemetry o OSQuery / EDR / DNS / WAF logs

  • Proven ability to write:

o Source type definitions o Field extraction rules o Correlation logic o Detection playbooks Cybersecurity Knowledge & Competency

  • Familiarity with MITRE ATT&CK, SIGMA rules, NIST 800-53 frameworks.

  • Experience supporting SOC, IR, SIEM, Detection Engineering, or Threat Ops teams.

  • Understanding modern attack techniques, identity abuse patterns, and cloud threats.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all