Accenture

Accenture

Posted via Workday

Security Architect

Posted Sep 21, 2026

Role at a glance

Job function
Software Engineering & IT Cybersecurity
Salary
Not Disclosed
Location
Gurugram
Work arrangement
On-site
Employment
Full-time
Experience
7+ years in SOC/IR including 4+ in IR L3 role.
Education
15 years full time education is required.

Spotted an issue?

We’ll check it against the original posting.

Log in to report

Role Summary

AI-generated

This role is an IR L3 analyst in a 24x7 security operations center and serves as the escalation point for complex and high-severity security incidents. The position leads technical investigations across endpoint, log, threat intelligence, cloud, and security orchestration tools, supporting containment, remediation, and continuous improvement.

What You'll Do

  • Own the end-to-end incident response lifecycle, including detection, containment, remediation, and recovery coordination.
  • Lead investigations of high-severity and critical incidents, including deep-dive analysis, forensics, threat hunting, and root cause...
  • Perform endpoint forensic triage with SentinelOne and detailed log analysis, correlation, and anomaly detection in Splunk.
  • Develop and optimize Splunk detection logic, SPL queries, dashboards, correlation rules, and automated response workflows.
  • Coordinate containment with IT teams, oversee recovery steps, and produce post-incident reports and RCA documentation.
  • Mentor L1 and L2 analysts, conduct playbook testing and updates, and present findings and metrics to leadership.

Generated from the employer's posting. Verify important details before applying.

View full posting

Qualifications

Minimum 5 years of experience in Security Information and Event Management (SIEM); experience in SOC/IR and IR L3 incident response; proficiency with Splunk SIEM, SPL queries, dashboards, correlation rules, SentinelOne, endpoint forensics, threat hunting, malware analysis, cloud incident handling in AWS and Azure, and Python, PowerShell, Bash, regex, or shell scripting.

Required

  • Security Information and Event Management (SIEM)
  • Splunk SIEM, including rule optimization, anomaly detection, ATT&CK mapping, dashboards, and SPL
  • SentinelOne forensic and incident response capabilities
  • Incident detection, investigation, containment, remediation, and root cause analysis
  • Endpoint, memory, file system, and log forensics
  • Threat hunting using TTPs
  • Cloud incident handling in AWS and Azure
  • Python, PowerShell, Bash, regex, or shell scripting

Original job description

Content provided by the employer

Project Role : Security Architect
Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.
Must have skills : Security Information and Event Management (SIEM)
Good to have skills : NA
Minimum 5 year(s) of experience is required
Educational Qualification : 15 years full time education

Summary:
As the IR L3 analyst in 24x7 SOC, you will be the escalation point for all complex and high severity security incidents and lead the technical handling of critical security incidents. You ll be responsible for deep-dive analysis, root cause investigation, forensics, and containment using tools such as Sentinal One, Splunk SIEM. This role requires deep expertise in detection, investigation, containment, and remediation, as well as collaboration with multiple teams across security, IT, and compliance.

Roles & Responsibilities:
-End-to-End Incident Response Ownership: Ability to handle incident lifecycle (detect, contain, remediate)
-Subject matter expert for handling the escalated high, critical or actual true positive incidents.
-Identify opportunities for automation and work with SIEM Platform Support team for implementing it.
-EDR Deep Dive: Using Real Time Response (RTR), Threat Graph, custom IOA rules
-Proficiency in writing SPL queries, dashboards, correlation rules, and tuning use cases
-Threat Hunting: Behavior-based detection using TTPs
-Deep understanding of malware, lateral movement, privilege escalation, and exfiltration patterns
-Threat Intel Integration: Automation of IOC lookups and enrichment flows
-Forensic Skills: Live host forensics, log correlation, malware behavioral analysis
-Deep experience in advanced threat detection and incident response
-Scripting Proficiency: Python, PowerShell, Bash for automation or ETL
-Proficiency in Sentinal One forensic and incident response capabilities
-Playbook Development: Able to define, update, and optimize IR playbooks and workflows
-Red team/purple team exposure
-Forensic analysis (memory, file systems, logs)
-Cloud incident handling (AWS, Azure)
-Dashboarding: Advanced visualizations and business-focused metrics in Splunk
-Certifications: Splunk Certified Admin/ES Admin, SC-200, or SOAR, Sentinal One EDR vendor training



Professional & Technical Skills:
Lead high-severity incident response, coordinating with stakeholders and IT teams
-Perform endpoint forensic triage using Sentinal One
-Conduct detailed log analysis and anomaly detection in Splunk
-Perform log correlation in Splunk to trace attack patterns, scope, and impact.
-Conduct deep-dive analysis into suspicious behaviors using SPL and custom dashboards
-Use endpoint data, network logs, and threat intel to drive full-lifecycle incident handling
-Isolate affected systems, coordinate containment with IT, and oversee recovery steps
-Recommend and define automated workflows for triage, enrichment, and response
-Perform root cause analysis and support RCA documentation.
-Create or optimize Splunk detection logic to improve fidelity and coverage
-Mentor L1 and L2 analysts through case walk-throughs and knowledge sharing
-Generate post-incident reports and present findings to leadership
-Lead investigations and coordinate response for major incidents
-Perform root cause analysis and post-incident reviews
-Participating in continuous improvement initiatives
-Conduct playbook testing, version control, and change documentation
-Contribute to executive-level reports, RCA documents, and compliance metrics
-SentinelOne AI : Custom detections, forensic triage, threat graphs
-Email Security : Proofpoint
-SOAR : XSOAR / Tines
DLP / Data Security
Splunk SIEM (core + ES module): Rule optimization, anomaly detection, ATT&CK mapping
Threat Intelligence: TTP mapping, behavioral correlation
Scripting: Python, regex, shell scripting for ETL workflows
-7+ years in SOC/IR including 4+ in IR L3 role. Experience in 24x7 environments, shift-based operations, or critical infrastructure response


Additional Information:
- The candidate should have minimum 5 years of experience in Security Information and Event Management (SIEM).
- This position is based at our Gurugram office.
- A 15 years full time education is required.

15 years full time education

About Accenture

Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.

Visit us at www.accenture.com 

Equal Employment Opportunity Statement


We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, military veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.

Accenture

About the company

Accenture

Large Enterprise

Accenture is a global professional services company that specializes in providing consulting, technology, and outsourcing services. With a diverse range of industries served, including financial services, healthcare, and telecommunications, Accenture leverages advanced technologies and data analytics to help organizations improve their performance and drive innovation. Committed to sustainable progress, the company emphasizes its dedication to inclusivity, digital transformation, and building a more sustainable future for its clients and communities. With a presence in over 120 countries, Accenture is known for its expertise in integrating cutting-edge solutions that address complex business challenges.