SIEM Content Development Specialist - Cyber Defence - VOIS
Pune, IndiaPosted Jul 21, 2026
Skip to main contentCareersDashboardProfileEnglishJoin Talent NetworkSign InSingle PositionIf we can connect, we can create a better future. Join us.View All JobsHybridSIEM Content Development Specialist - Cyber Defence - VOISPune, Maharashtra, IndiaApply NowFind out how well you match with this jobUpload your resumeJob descriptionPerks and benefitsRequisition ID285391Date posted07/20/2026Who we are
VOIS (Vodafone Intelligent Solutions) is a strategic arm of Vodafone Group Plc, creating value for customers by delivering intelligent solutions through Talent, Technology & Transformation. As the largest shared services organisation in the global telco industry with 30,000 FTE, our portfolio of next-generation solutions and services are designed in partnership with customers across Vodafone Group, local markets, and partner markets to simplify and drive growth. With our strategic partner Accenture, we work alongside our Vodafone customers, other Telco and tech companies to drive transformation, meet the challenges of our industry and ensure we stay relevant and resilient. This partnership is a unique, industry-first model which brings together the best of in-house and 3rd party capability. We work with customers across 28 countries from 10 VOIS locations: Albania, Egypt, Hungary, India, Romania, Spain, Turkey, UK, Germany, Ireland, and with a network of teams in Czech Republic, Italy, Greece, and Portugal. #VOIS #BeUnrivalled #CreateTheFutureAbout this Role
We are seeking a SIEM Content Development Specialist to strengthen Cyber Defence detection capabilities within the Cyber Security Operations Centre (CSOC). The role focuses on developing and refining SIEM detection content, leveraging knowledge of threat landscapes, MITRE ATT&CK techniques, and organisational risks. The individual will work closely with stakeholders to create actionable detection logic, enhance threat visibility, and improve response efficiency across Vodafone’s cyber defence ecosystem.What you’ll do
Design, develop, and optimise SIEM detection content across existing and new platformsLead and contribute to SIEM content engineering initiatives, applying SDLC and Agile methodologiesContinuously refine detection rules and logic to improve SOC efficiency and effectivenessDevelop and integrate threat response workflows and playbooksConduct threat analysis to design behavioural and indicator-based detection use casesCollaborate with log source owners to translate business and technical requirements into actionable SIEM contentDeliver cyber security reports and advisories to key stakeholdersPerform post-incident analysis and drive improvements through actionable insightsSupport EDR/XDR detection engineering and tuning activitiesCreate and maintain technical documentation, workflows, and operational playbooksWho you are
Experienced professional with 10+ years in SOC operations, SIEM content development, threat hunting, or security engineeringSkilled in SIEM technologies, particularly Elastic/ELK, with knowledge of platforms such as Splunk, Sentinel, ArcSight, or ChronicleProficient in programming and scripting (e.g., Python, SQL, JavaScript, PowerShell, KQL, ES|QL)Strong understanding of cloud environments (AWS, Azure, GCP) and associated telemetryExperienced in developing detection use cases and threat scenarios aligned with MITRE ATT&CK and cyber kill chain frameworksCompetent in Regex and data analysis techniquesKnowledgeable in networking concepts (TCP/IP, CIDR, subnets) and security tools (IDS/IPS, firewalls, AV systems)Strong analytical, problem-solving, and communication skillsAble to work independently, prioritise tasks, and collaborate effectively across teamsCertifications such as CISSP or SANS (e.g., GCIH, GCIA) are advantageousNot a perfect fit?
Concerned you may not meet every requirement? Vodafone is committed to creating an inclusive workplace where everyone can thrive. If you are excited about this role but your experience does not align exactly with...