Senior Security Engineer – SIEM & Detection Engineering
Mattel
- Location
- Hyderabad, , India
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- Posted
- 2h ago
Skills
About this role
Company Description
CREATIVITY IS OUR SUPERPOWER. It’s our heritage and it’s also our future. Because we don’t just make toys. We create innovative products and experiences that inspire fans, entertain audiences and develop children through play. Mattel is at its best when every member of our team feels respected, included, and heard—when everyone can show up as themselves and do their best work every day. We value and share an infinite range of ideas and voices that evolve and broaden our perspectives with a reach that extends into all our brands, partners, and suppliers.
Job Description
The Senior Security Engineer – SIEM & detecting Engineering is responsible for designing, implementing, and optimizing Mattel’s SIEM, NDR, and XDR ecosystems to ensure comprehensive global detection and response coverage. This role requires deep expertise in security telemetry, log management, and detection engineering, with hands-on experience developing scalable analytics, alerts, and integrations that strengthen detection posture, accelerate response, and enhance operational efficiency. Roles and Responsibilities Architect, implement, and maintain SIEM infrastructure to ensure reliable log ingestion, parsing, correlation, and alerting across enterprise systems. Develop and fine-tune detection content and analytics rules to identify suspicious or malicious activity across endpoints, networks, and cloud environments. Manage and enhance Network Detection and Response (NDR) and Extended Detection and Response (XDR) platforms, integrating telemetry for end-to-end visibility. Partner with the SOC and Incident Response teams to improve alert fidelity, reduce false positives, and accelerate investigation workflows. Integrate SIEM with SOAR and automation pipelines to support rapid response and consistent case handling. Collaborate with infrastructure and application teams to ensure comprehensive log coverage and compliance with data retention and privacy requirements. Develop and maintain dashboards, metrics, and reporting to measure detection performance and operational efficiency. Conduct periodic health checks, tuning, and performance optimization for SIEM and NDR solutions. Maintain detailed documentation, playbooks, and SOPs supporting SIEM and NDR operations.
Skills and Qualifications
Required: 5–8 years of experience in security engineering, detection engineering, or SOC architecture in an enterprise environment. Expert-level knowledge of SIEM platforms (e.g., Splunk, XSOAR, or equivalent), including onboarding, parsing, rule creation, and optimization. Strong understanding of detection engineering, including attack chain mapping, MITRE ATT&CK coverage, and event correlation. Experience with log source onboarding (firewalls, proxies, endpoints, cloud, identity, email systems etc.). Familiarity with SOAR tools and automation workflows for triage and enrichment. Strong scripting skills (Python, PowerShell, or Bash) for rule automation, parsing, and enrichment. Understanding of cloud detection engineering across Azure, AWS, or GCP environments. Excellent analytical, problem-solving, and communication skills, with a focus on collaboration and data-driven decision-making. SIEM engineering and administration (Splunk, Sentinel, etc.) Log collection, parsing, and correlation logic development NDR/XDR deployment and tuning (e.g., ExtraHop, Vectra, Cisco, CrowdStrike, or similar) Detection engineering and content lifecycle management Cloud detection coverage (Azure, AWS, GCP) Scripting and automation (Python, PowerShell, Bash) SOAR integration for alert enrichment and response automation Data normalization, threat hunting, and query development Familiarity with the MITRE ATT&CK and D3FEND frameworks Network security, endpoint telemetry, and identity-based detection techniques Preferred: Bachelor’s