SOC - Detection Engineer
At Capgemini Engineering, the world leader in engineering services, we bring together a global team of engineers, scientists, and architects to help the world’s most innovative companies unleash their potential. From autonomous cars to life-saving robots, our digital and software technology experts think outside the box as they provide unique R&D and engineering services across all industries. Join us for a career full of opportunities. Where you can make a difference. Where no two days are the same.
Your Role
- Design, develop, and continuously improve detection use cases, analytics rules, correlation logic, anomaly detection models, threat hunting queries, dashboards, and watchlists across Microsoft Sentinel, Defender XDR, and related security platforms.
- Translate threat intelligence, incident findings, red/purple team outcomes, emerging threats, and business risks into prioritized detection requirements aligned with organizational security objectives and MITRE ATT&CK coverage.
- Create, test, validate, tune, and maintain detection logic using KQL, Python, PowerShell, and detection-as-code methodologies while minimizing false positives and improving detection effectiveness.
- Collaborate with SOC, Data Onboarding, and Security Automation teams to ensure telemetry readiness, SOAR integration, operational validation, documentation, and successful production deployment of detections.
- Conduct threat hunting, attack emulation, behavioral analytics, and continuous detection coverage assessments while maintaining detection lifecycle governance, quality metrics, release management, and ongoing enhancements.
Your Profile
- 6+ years of experience in Detection Engineering, Threat Hunting, and Security Analytics with demonstrated ownership of the end-to-end detection lifecycle, content validation, and cross-domain threat detection capabilities.
- Strong expertise in Microsoft Sentinel, Microsoft Defender XDR, Azure Data Explorer (ADX), KQL, Python, PowerShell, and detection engineering best practices, including analytics development, tuning, testing, and operationalization of security content.
- Hands-on experience with CI/CD, Git, Infrastructure-as-Code (IaC), Detection-as-Code, testing automation, content repositories, platform integrations, peer review processes, and detection release management within SOC environments.
- Experience working with Azure Data Explorer, Databricks, Jupyter/iPython Notebooks, MSTICPy, security data science, statistical/ML analytics, and data engineering concepts to develop and operationalize advanced hunting, anomaly detection, and behavioral analytics use cases.
- Proven experience with attack emulation and detection validation frameworks such as Atomic Red Team, Caldera, Prelude, AttackIQ, Sigma, YARA/YARA-L, as well as fraud, identity, cloud, SaaS, OT, data leakage, and network anomaly detection use cases.
What you will love working in Capgemini
- Design, develop, and continuously enhance detection use cases, analytics rules, correlation logic, anomaly detection models, threat hunting queries, dashboards, and watchlists using Microsoft Sentinel, Microsoft Defender XDR, and related security platforms.
- Create, validate, tune, and maintain detection logic using KQL, Python, PowerShell, and detection-as-code methodologies while reducing false positives and improving overall detection effectiveness.
- Clear career progression paths from engineering roles to architecture and consulting.
- Be part of mission-critical projects that ensure security, compliance, and operational efficiency for Fortune 500 clients.
Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem.
Bangalore, IN