SOC - Detection Engineer

Capgemini

9–12 yrs Bengaluru, Chennai, Gurugram, Hyderabad, Kolkata, Navi Mumbai, Noida, Pune Full Time Hybrid (office + remote)
Capgemini logo
Posted : today
Actively hiring

Job description

Join Capgemini and take charge of your career! We're seeking a skilled SOC – Detection Engineer to elevate our enterprise-scale security detection and threat hunting capabilities. This role is ideal for professionals with expertise in Microsoft Sentinel, Defender XDR, KQL, Python, Threat Hunting, and Detection Engineering.

Bring your talents to an organization where you can shape your professional path, collaborate with a global community, and drive innovation. We empower you to reimagine what's possible and help leading organizations unlock technology's value for a more sustainable and inclusive world.

Responsibilities

Key responsibilities include designing, developing, and refining detection use cases, analytics rules, correlation logic, and anomaly detection models across Microsoft Sentinel, Defender XDR, and related platforms. You'll translate threat intelligence, incident findings, and emerging threats into actionable detection requirements, ensuring robust MITRE ATT&CK coverage.

This role involves creating, testing, and validating detection logic using KQL, Python, and PowerShell, while employing detection-as-code methodologies to minimize false positives. You will collaborate closely with SOC and Data Onboarding teams to ensure telemetry readiness and successful deployment of detections. Furthermore, you'll conduct threat hunting, attack emulation, and continuous detection coverage assessments.

Qualifications

We are looking for candidates with extensive experience in Detection Engineering, Threat Hunting, and Security Analytics, demonstrating ownership of the full detection lifecycle. A strong command of Microsoft Sentinel, Microsoft Defender XDR, Azure Data Explorer (ADX), KQL, Python, and PowerShell is essential.

Hands-on experience with CI/CD, Git, Infrastructure-as-Code, Detection-as-Code, and automated testing is required. Familiarity with attack emulation frameworks like Atomic Red Team and detection validation concepts is highly valued. Experience with data science and machine learning analytics to develop advanced hunting and anomaly detection use cases is a significant advantage.

Essential Skills

Microsoft SentinelMicrosoft Defender XDRKQLPythonThreat HuntingDetection EngineeringAzure Data ExplorerPowerShellCI/CDGitInfrastructure-as-CodeDetection-as-CodeAttack EmulationData ScienceMachine Learning

Good to Have

DatabricksJupyter NotebooksMSTICPySigmaYARACalderaPreludeAttackIQSOAR

Highlights

  • Actively hiring

More Details

RoleSOC - Detection Engineer
IndustryInformation Technology & Services
DepartmentInformation Technology, Engineering, Security
Employment TypeFull Time, Hybrid (office + remote)

About the Company

Capgemini logo

Capgemini

Information Technology & Services

SOC - Detection Engineer at Capgemini | SkillMX | SkillMX