Find your next job. Start today.

Direct from employer

Sr Subject Matter Expert (Support&Ops)

Date Posted: Oct 01, 2026

Job Detail

  • location_on
    Location Pune, Maharashtra, India
  • desktop_windows
    Job Type: Full Time/Permanent
  • schedule
    Shift:
  • analytics
    Career Level:
  • group
    Positions:
  • calendar_view_day
    Experience:
  • male
    Gender: No Preference
  • school
    Degree:
  • calendar_month
    Apply Before: Nov 15, 2026

Job Description

Job Summary

Years of Experience

  • 12+ years of experience in SIEM engineering, Splunk administration, security analytics, detection engineering, and enterprise log-management environments.

General Description

  • Serve as the L3 SME for Customer’s Splunk Cloud managed service, responsible for advanced troubleshooting, engineering, optimization, and technical governance. 
  • Lead complex data onboarding, detection-content engineering, advanced dashboarding, alert tuning, performance optimization, and RCA support. 
  • Provide technical oversight to L2 engineers and collaborate with Customer, SOC/MSSP, IAM, PAM, AppSec, DevOps, network, cloud, and application teams. 

 

 

Key Responsibilities

Years of Experience

  • 12+ years of experience in SIEM engineering, Splunk administration, security analytics, detection engineering, and enterprise log-management environments.

General Description

  • Serve as the L3 SME for Customer’s Splunk Cloud managed service, responsible for advanced troubleshooting, engineering, optimization, and technical governance. 
  • Lead complex data onboarding, detection-content engineering, advanced dashboarding, alert tuning, performance optimization, and RCA support. 
  • Provide technical oversight to L2 engineers and collaborate with Customer, SOC/MSSP, IAM, PAM, AppSec, DevOps, network, cloud, and application teams. 

 

 

Skill Requirements

Technical Requirements

  • Hands-on experience with Splunk Enterprise and/or Splunk Cloud in enterprise environments. 
  • Experience with SPL searches, dashboards, reports, alerts, field extractions, sourcetypes, indexes, and knowledge objects. 
  • Experience in log-source onboarding, ingestion validation, parsing, field mapping, data-quality checks, and pipeline troubleshooting. 
  • Knowledge of SIEM operations, security monitoring, incident investigation, RCA evidence, and operational reporting. 
  • Experience integrating Splunk with IAM, PAM, SSO, EDR, cloud, network-security, application, and infrastructure data sources. 
  • Experience with ServiceNow/Jira, incident, request, change, and problem management processes. 
  • Ability to maintain use-case catalogues, data-source inventories, dashboard inventories, runbooks, and service metrics. 
  • Advanced SPL development and optimization, data models, accelerated searches, correlation searches, macros, lookups, and enterprise-scale dashboard design. 
  • Strong experience in detection engineering, MITRE ATT&CK mapping, use-case lifecycle management, tuning methodology, and security-content governance. 
  • Experience troubleshooting complex ingestion architecture, heavy forwarders, universal forwarders, HEC, APIs, cloud integrations, and data-routing issues. 
  • Knowledge of Splunk Cloud architecture, search performance, ingestion forecasting, retention, index strategy, and cost/license optimization. 
  • Ability to lead RCA, problem management, technical reviews, platform upgrades, automation, and continuous-improvement initiatives. 
  • Experience with Python, REST APIs, Git, CI/CD, and automation of Splunk administration and content deployment. 

Soft Skills

  • Excellent communication and presentation skills.
  • Strong problem-solving and critical thinking skills.
  • Exceptional project management and organizational abilities.
  • Team collaboration and leadership skills.
  • Client-focused approach with a commitment to delivering exceptional customer service.

Certifications (Good to have)

Good to have relevant certificates like (any of the below):

  • Splunk Enterprise Certified Admin, Splunk Cloud Certified Admin, or Splunk Enterprise Security Certified Admin. 
  • CISSP, GCIA, GCIH, CySA+, or equivalent security certification is preferred.

Educational Qualifications

  • University degree in IT or/and IT Security.
  • Bachelor’s degree in computer science/ IT or any relevant fields.

 

Other Requirements

Source: HCLTech careers — Read the original posting and apply

This role is listed by the employer on its own careers site. Kaam Ki Khoj does not process applications for it.

Company Overview

HCLTech
HCLTech · Noida, Uttar Pradesh, India
388 open roles

HCLTech is an employer in the IT/Computers - Software, Software Services sector with operations in India. This is a directory listing maintained by Kaam Ki Khoj so that candidates can find the organisation; it is not an official company page and Kaam... Read More

Related Jobs

One upload, every employer

Let the right employer find you

Upload your CV once — we read it, build your profile and put you in front of every employer hiring on Kaam Ki Khoj. No forms, no fees.

Upload your CV Browse jobs