The Senior Security Engineer β SIEM & detecting Engineering is responsible for designing, implementing, and optimizing Mattelβs SIEM, NDR, and XDR ecosystems to ensure comprehensive global detection and response coverage. This role requires deep expertise in security telemetry, log management, and detection engineering, with hands-on experience developing scalable analytics, alerts, and integrations that strengthen detection posture, accelerate response, and enhance operational efficiency. 
Roles and Responsibilities 
β’ Architect, implement, and maintain SIEM infrastructure to ensure reliable log ingestion, parsing, correlation, and alerting across enterprise systems. 
β’ Develop and fine-tune detection content and analytics rules to identify suspicious or malicious activity across endpoints, networks, and cloud environments. 
β’ Manage and enhance Network Detection and Response (NDR) and Extended Detection and Response (XDR) platforms, integrating telemetry for end-to-end visibility. 
β’ Partner with the SOC and Incident Response teams to improve alert fidelity, reduce false positives, and accelerate investigation workflows. 
β’ Integrate SIEM with SOAR and automation pipelines to support rapid response and consistent case handling. 
β’ Collaborate with infrastructure and application teams to ensure comprehensive log coverage and compliance with data retention and privacy requirements. 
β’ Develop and maintain dashboards, metrics, and reporting to measure detection performance and operational efficiency. 
β’ Conduct periodic health checks, tuning, and performance optimization for SIEM and NDR solutions. 
β’ Maintain detailed documentation, playbooks, and SOPs supporting SIEM and NDR operations. 
Skills and Qualifications 
Required: 
β’ 5β8 years of experience in security engineering, detection engineering, or SOC architecture in an enterprise environment. 
β’ Expert-level knowledge of SIEM platforms (e.g., Splunk, XSOAR, or equivalent), including onboarding, parsing, rule creation, and optimization. 
β’ Strong understanding of detection engineering, including attack chain mapping, MITRE ATT&CK coverage, and event correlation. 
β’ Experience with log source onboarding (firewalls, proxies, endpoints, cloud, identity, email systems etc.). 
β’ Familiarity with SOAR tools and automation workflows for triage and enrichment. 
β’ Strong scripting skills (Python, PowerShell, or Bash) for rule automation, parsing, and enrichment. 
β’ Understanding of cloud detection engineering across Azure, AWS, or GCP environments. 
β’ Excellent analytical, problem-solving, and communication skills, with a focus on collaboration and data-driven decision-making. 
β’ SIEM engineering and administration (Splunk, Sentinel, etc.) 
β’ Log collection, parsing, and correlation logic development 
β’ NDR/XDR deployment and tuning (e.g., ExtraHop, Vectra, Cisco, CrowdStrike, or similar) 
β’ Detection engineering and content lifecycle management 
β’ Cloud detection coverage (Azure, AWS, GCP) 
β’ Scripting and automation (Python, PowerShell, Bash) 
β’ SOAR integration for alert enrichment and response automation 
β’ Data normalization, threat hunting, and query development 
β’ Familiarity with the MITRE ATT&CK and D3FEND frameworks 
β’ Network security, endpoint telemetry, and identity-based detection techniques 
 
Preferred: 
β’ Bachelorβs degree in Cybersecurity, Computer Science, or related technical field, or equivalent professional experience. 
β’ Demonstrated success designing, scaling, and maintaining enterprise SIEM and detection systems. 
β’ Certifications such as GIAC Certified Detection Analyst (GCDA), GIAC Security Operations Certified (GSOC), CompTIA CySA+, ISC2 SSCP, Splunk Enterprise Security Certified Admin or Architect, or equivalent detection engineering or SIEM certification 
β’ Analytical and detail-oriented with a focus on precision and reliability 
β’ Strong communication and collaboration across technical and non-technical stakeholders 
β’ Adaptable and proactive in a fast-paced, global environment 
β’ Passion for continuous learning, innovation, and automation in security operations 
β’ Effective mentor and team contributor 
Shift Timing:  
05:00β14:00 PST (18:30β03:30 IST), Monday through Friday, with emergency on-call duties as needed