Corporate · onsite · online training worldwide
contact@DevOpsSchool.com· +91 99057 40781·
> SIEM & Security Analytics · DevOpsSchool Trainer

Securonix Trainer

Private corporate batches, live online cohorts and 1-on-1 mentoring in SIEM and UEBA detection engineering — ingestion, behaviour analytics, threat chains and investigation workflow — taught by a practitioner who runs it in production.

20 years across DevOps, SRE and Security · 10,000+ engineers trained · Trained teams at JPMorgan Chase, Verizon, Nokia and the World Bank

DeliveryOnline · Onsite · Hybrid
FormatsCorporate · 1-on-1 · Cohort
AgendaCustomisable
Batch size8–30 engineers
Engineers we've trained work at
JPMorgan ChaseBank of AmericaWells FargoVerizonNokiaWorld BankGE HealthcareVMwareOracleQualcommMercedes-BenzAirbusDatadogSplunkDeloitteInfosysWiproCapgemini
# who teaches it

Your Securonix trainer

Rajesh Kumar

Principal DevOps Engineer & Architect

DevSecOpsSecurity engineeringPipeline hardening20 years in productionPrincipal / architect roles10,000+ engineers trainedM.Tech BITS Pilani25+ certifications

Rajesh teaches Securonix as detection engineering rather than console navigation: how data actually arrives and gets parsed into a normalised event model, why identity and asset context determines whether behavioural baselines mean anything, and how policy types — rule-based, behavioural, rarity, land-speed and beaconing — differ in what they can and cannot catch. Sessions cover Spotter search and investigation workflow, threat chains and risk scoring, ATT&CK mapping and coverage gaps, whitelisting and tuning with a defensible false-positive budget, and the content lifecycle that keeps a detection set improving — all framed as defending an estate you own, with every lab run against attendee-provisioned data.

Twenty years across DevOps, SRE and Security, in principal and architect roles at PayPay, SoftwareAG, ServiceNow, JDA Software, Intuit, Adobe and others. He has trained engineers at JPMorgan Chase, Verizon, Nokia, the World Bank, VMware, Oracle, Mercedes-Benz and Airbus — more than 10,000 people personally. He teaches what he runs, not what he reads.

One practitioner, not a bench

You are booked with a named engineer, and that is who turns up. Marketplaces and larger providers rotate whoever is free, so the person who sold you the agenda is rarely the person teaching it.

The same trainer is available for the next engagement, which matters when a team builds on what it learned last time.

18,000+certified learners
500+corporate batches delivered
50+countries served
100+certification programmes
# faculty

Who delivers Securonix engagements

Your batch is assigned a named trainer before it starts, and that is who teaches it. See the full faculty.

How your Securonix trainer is chosen

Engagements are matched on the tool, not the calendar. For Securonix that means a trainer who has run it in production — SIEM and UEBA detection engineering — ingestion, behaviour analytics, threat chains and investigation workflow — rather than whoever is free that week. You are told who is teaching before you commit, and that person is on the discovery call that shapes the agenda.

Where a batch is large enough to need a second trainer, the pairing is declared up front. The lead trainer stays accountable for the syllabus and the assessment either way.

Rajesh Kumar

Principal DevOps Engineer & Architect

India20 yrsLead trainer

Twenty years across DevOps, SRE and Security in principal and architect roles at PayPay, SoftwareAG, ServiceNow, JDA Software, Intuit, Adobe, IBM/Emptoris, Ness, MindTree and Accenture. He has trained more than 10,000 engineers personally, at organisations including JPMorgan Chase, Verizon, Nokia, the World Bank, VMware, Oracle, Mercedes-Benz and Airbus. He teaches what he runs, not what he reads.

Nikhil Gupta

IndiaInstructorCoach

Pranab Kumar

IndiaInstructorCoach

Rohit Ghatol

IndiaInstructorCoach

Amit Agarwal

IndiaInstructorCoach

Anil Kumar

IndiaInstructorCoach

Balachandran Anbalagan

IndiaInstructorCoach

Durga Prasad

IndiaInstructorCoach

Gaurav Aggarwal

IndiaInstructorCoach

Harsh Mehta

IndiaInstructorCoach

Kapil Gupta

IndiaInstructorCoach

Kunal Jain

IndiaInstructorCoach

# how to engage

Four ways to work with this trainer

Private corporate batch

Teams of 8–30

Custom agenda, your timezone, onsite or online, NDA-friendly.

Request a quote

1-on-1 mentoring

Individual engineers

A private instructor and a curriculum built around your goal.

₹99,999

Live & Interactive cohort

Individuals who want peers

Scheduled batch, max 8 to 10 hours of live instruction.

₹34,999

Self-paced video

Self-starters

Full LMS access — 20+ courses and 50+ tools included.

₹833/mo
# private batches

Private Securonix training for your team

A private batch starts with a discovery call. We look at the stack you actually run — the CI system, the cloud, the constraints — and map the agenda onto it, so examples use your topology rather than a generic one.

Delivery is onsite at your premises, live online, or hybrid, scheduled around your release calendar rather than ours. Batches run 8 to 30 engineers.

Every attendee leaves with recordings, slides, lab repositories and a completion certificate. You receive an attendance and assessment report. Invoicing supports PO and GST.

Talk to us about a private Securonix batch

What you provide vs what we bring

  • You: the room or the call, and the engineers
  • Us: trainer, agenda, labs, assessment, certificates
  • Labs: we guide your team through provisioning their own free-tier cloud environment — the skill goes with them
# the technology

What is Securonix?

Securonix is a security information and event management platform with user and entity behaviour analytics at its core. It collects log and event data from across an estate — identity providers, endpoints, firewalls, proxies, cloud control planes, SaaS applications, databases and custom applications — normalises it into a common event model, enriches it with identity and asset context, and then applies both signature-style rules and behavioural models to surface activity that warrants a human decision.

The behavioural half is what distinguishes Securonix from a pure log search platform. Rather than only asking whether an event matches a known-bad pattern, it builds baselines for each user, host, service account and peer group and scores deviation from them: a first-time administrative action, a login from a location that is impossible given the previous one, access to a data store the account has never touched, an outbound connection at an interval that looks like beaconing. Individual violations accumulate into a risk score on the entity, and threat chains stitch related violations into a single narrative that maps onto ATT&CK stages instead of arriving as forty separate alerts.

Operationally, Securonix is used as the detection and investigation layer of a security operations function. Analysts search normalised data with Spotter, work incidents in an investigation workbench that carries entity context with it, and drive containment through playbooks and integrations with ticketing, identity and endpoint tooling. Around that sits the work that actually determines whether the platform is useful: onboarding data sources with correct parsing, keeping identity and asset context current, writing and tuning policies, and retiring the ones that only generate noise.

Why this skill matters now

Security operations teams are drowning in telemetry and short of analysts. Estates now span on-premises infrastructure, several clouds, dozens of SaaS applications and a remote workforce, and every one of those produces logs. Correlation rules alone do not scale to that, because the interesting activity is frequently a legitimate credential doing something unusual rather than a known-bad signature.

That is the gap behaviour analytics is meant to close, and it is why insider threat, compromised credentials and cloud account misuse dominate the detection roadmaps that boards now ask about. Regulatory pressure reinforces it: retention, audit evidence, breach notification timelines and sector-specific controls all assume you can demonstrate what happened and when.

The scarce skill is not operating the console. It is detection engineering — deciding which data sources actually earn their ingestion cost, getting parsing and normalisation right so a field means the same thing across twelve sources, keeping identity context accurate enough for behavioural baselines to be meaningful, writing policies with a defensible false-positive rate, and running a content lifecycle so the detection set improves rather than accumulates. Teams that skip that work end up with an expensive platform and an alert queue nobody reads.

Securonix training
# outcomes

What your team can do afterwards

Explain the Securonix architecture end to end — collection, parsing, enrichment, analytics, storage and presentation — and where each stage fails
Onboard a data source correctly: connector selection, parser development, field mapping to the normalised event model and validation
Build and maintain identity, asset and peer-group context so behavioural baselines are meaningful rather than noise
Write both rule-based and behaviour-based policies, and choose correctly between them for a given detection objective
Interpret risk scoring and threat chains, and explain to a stakeholder why an entity surfaced
Search and pivot in Spotter, and run an investigation from first alert to documented conclusion
Tune detections against a false-positive budget using whitelists, watchlists and threshold analysis rather than switching policies off
Map detection coverage to MITRE ATT&CK, identify gaps and run a content lifecycle that closes them
# curriculum

7 modules. Live demos in a real lab, not slides.

01SIEM, UEBA and the detection problemLive & Interactive5 hrs · 2 assignments · 1 capstone

The problem before the platform. Why correlation rules alone stopped scaling, what behaviour analytics adds and what it cannot do, and an honest framing of Securonix against log-search-first platforms — including the operational cost that any SIEM imposes on the team that runs it.

Topics: What a SIEM is actually for: detection, investigation, evidence, compliance · The limits of signature and correlation-only detection · UEBA: baselines, peer groups and deviation scoring · Insider threat, compromised credentials and cloud account misuse as detection classes · Securonix positioned against log-centric SIEM platforms · The real operational cost of running a SIEM well · Detection engineering as a discipline, not a product feature

  • Assignments: (1) Write three detection objectives for your own estate and classify each as rule-based or behavioural; (2) Document the current detection coverage and blind spots of a team you work with
  • Capstone: Produce a detection strategy note that states what your SIEM is expected to catch and what it is not
02Architecture, deployment and data flowLive & Interactive5 hrs · 2 assignments · 1 capstone

How data physically gets in and where it lives. Cloud and self-managed deployment models, collection components and remote ingestion, the data lake and search tiers, retention and cost, multi-tenancy, and role-based access for an analyst team.

Topics: Deployment models: cloud-delivered and self-managed · Collection architecture and remote ingestion nodes · Message queues, batching and back-pressure behaviour · The data lake, indexing and search tiers · Retention tiers, archival and the cost model of ingestion · Multi-tenancy and data segregation · Users, roles, RBAC and least privilege for analysts · Platform health monitoring and ingestion lag alerting

  • Assignments: (1) Draw the full data path for one source from agent to analyst screen, naming every component it crosses; (2) Design an RBAC model separating analyst, engineer and administrator duties
  • Capstone: Deliver an architecture and retention design with a justified ingestion budget per data source
03Data ingestion, parsing and normalisationLive & Interactive5 hrs · 2 assignments · 1 capstone

The stage that determines whether anything downstream works. Connectors and collection methods, writing and testing parsers, mapping fields into the normalised event model, handling malformed and multi-line events, timestamp and timezone correctness, and validating that a source is genuinely complete.

Topics: Connector types: syslog, API, agent, cloud-native and file-based · Onboarding cloud sources: identity providers, cloud audit logs, SaaS applications · Parser development, regular expressions and structured formats · Mapping to the normalised event model and why field consistency matters · Timestamp, timezone and event-time versus ingest-time problems · Handling multi-line, truncated and malformed events · Validating source completeness and detecting silent collection failure · Ingestion cost control: filtering, sampling and what not to collect

  • Assignments: (1) Write and test a parser for a custom application log and prove every field maps correctly; (2) Build a monitor that alerts when a source stops sending
  • Capstone: Onboard three heterogeneous sources with validated parsing, correct timestamps and completeness monitoring
04Identity, asset and threat contextLive & Interactive5 hrs · 2 assignments · 1 capstone

Behavioural analytics is only as good as the context under it. Importing users and assets from directory and HR sources, entity resolution across identifiers, peer group construction, service and shared account handling, watchlists, and threat intelligence enrichment.

Topics: User import from directory and HR systems, and keeping it current · Asset and network context import · Entity resolution: linking accounts, hosts and identities to one entity · Peer groups: how they are built and what breaks them · Service accounts, shared accounts and non-human identities · Joiners, movers and leavers as a data quality problem · Watchlists for high-risk populations and departing employees · Threat intelligence feeds and enrichment at ingest

  • Assignments: (1) Import an identity source and resolve a set of accounts to correct entities; (2) Build a peer group model for a department and justify the grouping attribute
  • Capstone: Deliver an entity context model with documented refresh cadence and a data quality check for each source
05Detection engineering: policies, analytics and threat modelsLive & Interactive5 hrs · 2 assignments · 1 capstone

Writing detections that survive contact with production. Rule-based policies for known patterns, behavioural policies for deviation, rarity, land-speed and beaconing analytics, threshold selection, and assembling individual violations into threat models and chains that read as a narrative.

Topics: Policy types and choosing between rule-based and behavioural detection · Behaviour profiles, baselining periods and cold-start problems · Rarity, first-seen and volumetric analytics · Land-speed, impossible travel and geo-based detection · Beaconing and periodicity detection for command-and-control · Risk scoring, weighting and score decay · Threat models and threat chains across ATT&CK stages · Out-of-the-box content: what to adopt, what to modify, what to disable · Testing a detection safely before enabling it

  • Assignments: (1) Write a behavioural policy for privileged access misuse and validate it against historical data; (2) Build a threat chain that links at least four violations into one narrative
  • Capstone: Deliver a detection set for one attack scenario with policies, chain, risk weighting and validation evidence
06Investigation, response and case managementLive & Interactive5 hrs · 2 assignments · 1 capstone

What an analyst actually does at three in the morning. Searching and pivoting with Spotter, working an incident in the investigation workbench with entity context attached, evidence collection, playbook-driven response, integration with ticketing and identity tooling, and writing a conclusion someone else can audit.

Topics: Spotter search syntax, filtering and pivoting · Building an investigation timeline from violations and raw events · The investigation workbench and entity-centric analysis · Triage: separating a real detection from expected behaviour · Evidence collection and preserving audit integrity · Case management, assignment, escalation and handover · Automated response playbooks and safe containment actions · Integrations with ticketing, identity, endpoint and email security · Writing an incident conclusion that survives review

  • Assignments: (1) Run a full investigation from alert to written conclusion using only platform evidence; (2) Build a response playbook with a manual approval gate before any containment action
  • Capstone: Deliver a documented investigation and a tested response playbook for one detection class
07Tuning, content lifecycle, reporting and complianceLive & Interactive5 hrs · 2 assignments · 1 capstone

Keeping the platform useful in year two. Measuring false positives honestly, tuning with whitelists and thresholds rather than disabling detections, ATT&CK coverage mapping, content version control and promotion, dashboards and reporting for different audiences, and the audit evidence compliance functions ask for.

Topics: Measuring detection quality: false positive rate, precision, time to triage · Whitelisting and exception management with expiry and ownership · Threshold tuning against historical data instead of intuition · Retiring detections that never produce a true positive · MITRE ATT&CK coverage mapping and gap analysis · Content version control, promotion between environments and rollback · Dashboards for analysts, managers and executives · Compliance reporting, retention evidence and audit support · Onboarding a new data source as a repeatable process

  • Assignments: (1) Tune a noisy detection to an agreed false-positive budget and evidence the improvement; (2) Produce an ATT&CK coverage map with three prioritised gaps and a plan to close them
  • Capstone: Deliver a detection content lifecycle: intake, testing, promotion, measurement, tuning and retirement

Need this mapped to your stack?

We rebuild the agenda around the tools you actually run.

Request a custom agenda
# hands-on

Labs and capstones your engineers actually build

LAB · INGESTION

Onboard a source properly

Take a custom application log, write and test a parser, map every field to the normalised model and prove timestamps and completeness are correct.

parsersnormalisationconnectors
LAB · CONTEXT

Make the baselines mean something

Import identity and asset context, resolve accounts to entities, build peer groups and demonstrate how a bad grouping ruins a behavioural detection.

identityentity resolutionpeer groups
LAB · DETECTION

Write a behavioural policy that holds

Build a privileged-access-misuse detection, validate it against historical data, set thresholds from evidence and record its expected false positive rate.

uebapolicythresholds
LAB · CHAINS

Forty alerts, one story

Assemble related violations into a threat chain mapped across ATT&CK stages, and demonstrate the difference in analyst workload against ungrouped alerts.

threat chainsrisk scoringatt&ck
LAB · INVESTIGATION

Alert to written conclusion

Run a full investigation in Spotter and the workbench, collect evidence, and produce a conclusion another analyst could audit without asking you a question.

spottertriageevidence
CAPSTONE · CONTENT LIFECYCLE

A detection set that improves

Deliver intake, testing, promotion, measurement, tuning and retirement for a detection content set, with an ATT&CK coverage map and prioritised gaps.

tuningcoveragelifecycle
# ecosystem

The tools Securonix sits next to

Splunk
Elastic Security
MITRE ATT&CK
Active Directory
Okta
CrowdStrike
AWS CloudTrail
Azure Sentinel
Palo Alto Networks
ServiceNow
Kafka
Snowflake

Who this is for

  • SOC analysts moving from alert triage into detection engineering
  • Detection engineers responsible for the policy and content set
  • Security engineers onboarding data sources and maintaining parsers
  • Incident responders who need to investigate efficiently inside the platform
  • Insider threat and fraud teams using behaviour analytics on their own workforce data
  • Security architects and SOC managers evaluating coverage, cost and detection quality

Pre-requisites

  • Working understanding of security operations: alerts, triage, incidents and escalation
  • Familiarity with common log sources — authentication, endpoint, firewall, proxy and cloud audit logs
  • Comfortable with regular expressions and reading structured data formats such as JSON and CSV
  • Basic networking and identity concepts: DNS, TCP/IP, directory services and authentication flows
  • Access to a Securonix tenant or lab instance, or willingness to work through the guided sample dataset
# pricing

Straightforward pricing

Every plan includes 1 year of full LMS access — not just this course, the entire DevOpsSchool LMS: 20+ courses, 50+ tools, videos, quizzes, assignments and projects.

Self-paced video

₹833/mo

Billed yearly at ₹9,996

Enroll now

1-on-1 mentorship

₹99,999

Full program, private instructor

Enroll 1-on-1

Corporate / private batch

8–30 engineers · custom agenda · onsite or online · PO and GST invoicing

Get a custom quote

Refunds. If we cancel or postpone a cohort, you get a full refund within 15 days. There is no money-back guarantee otherwise.

Terms. Course material remains licensed to the attendee. Read the terms.

Your data. We don't share it with third parties. Privacy policy.

Every attendee gets a verifiable certificate

  • Issued per attendee on completion
  • Verifiable at devopsschool.com/certificates
  • Hard copy available on request
  • Corporate batches receive an attendance and assessment report
DevOpsSchool

Securonix Training

Certificate of completion

# feedback

What engineers say

4.4 / 5 from 26 reviews on Trustpilot.

★★★★★
Rajesh is a very good trainer I have experienced in DevSecOps training. The number of contents in different topics he has posted on the DevOpsSchool public website are amazing and user friendly for beginners and experienced professionals.
Ashutosh Mishra · Trustpilot
★★★★★
Very good training session. Well explained from the basics to the complex concepts. Also tried to cover practicals and demos within the 3 hour sessions. The learning content and videos are of a great deal of help.
Sreekanth Kannoth · Trustpilot
★★★★★
Basics explanation was exemplary from Rajesh where he dealt with complicated topics to be simple. Great learning stuff personally for me.
Krishna Mohan Yelleti · Trustpilot
★★★★★
Very detailed explanation and has lots of patience in attending the questionnaire. Thanks again for your wonderful sessions.
Uttam Samudrala · Trustpilot
★★★★★
Good discussion, helped us to understand different tools in SRE.
Prashant Saxena · Trustpilot
★★★★★
Got good lab sessions which kept the new DevOps tool learnings to the point and it helped a lot in my career.
robin son · Trustpilot
# comparison

Why a named practitioner beats a marketplace listing

What mattersYouTube + blogsGeneric online courseFreelance marketplaceDevOpsSchool
Named practitionerNoRarelyVaries per bookingYes — same trainer each time
Production experienceUnknownUnknownUnverified20 years, named employers
Custom agendaNoNoSometimesBuilt from your stack
Onsite deliveryNoNoSometimesYes
Lab environmentNoneSandbox that expiresVariesYour own cloud — skill goes with you
AssessmentNoneQuizRarelyAssignments + capstone per module
Per-attendee certificatesNoSometimesRarelyYes
Corporate invoicingNoLimitedVariesPO and GST
Post-training supportNoneForum, time-limitedNoneLifetime forum access
# questions

Frequently asked

Is this an offensive security course?
No. Every module is framed defensively — instrumenting, detecting and investigating activity in an estate you are responsible for. Attack techniques appear only as detection targets, so attendees understand what a policy is meant to catch and why it fails when it does.
Do we need our own Securonix tenant?
It is much better if you have one, and for private batches we build labs against your own environment and data sources. Where no tenant is available we work through a guided sample dataset that exercises the same ingestion, policy and investigation workflow.
Is this for analysts or for engineers?
Both, with different weighting. A private batch for a SOC leans towards Spotter, triage, investigation and case management; a batch for a platform team leans towards ingestion, parsers, entity context and content lifecycle. We set that split during the discovery call.
Can the agenda be customised for our stack?
Yes — that is the normal case for a private batch. We look at the data sources you actually ingest, your identity provider, your cloud footprint and your ticketing system, and rebuild the modules and labs around them.
How much of this transfers to another SIEM?
A large share. Ingestion and parsing discipline, entity context quality, behavioural detection design, ATT&CK coverage mapping and content lifecycle are platform-independent. The console, search syntax and policy editor are the Securonix-specific parts.
Our alert queue is unmanageable. Does the course address that?
Directly. The tuning module covers measuring false positive rate honestly, threshold selection from historical data, whitelisting with ownership and expiry, threat chaining to collapse related alerts, and retiring detections that have never produced a true positive.
Do you deliver onsite?
Yes. Private batches run onsite at your premises, live online, or hybrid. You provide the room and the engineers; we bring the trainer, agenda, labs, assessment and certificates.
How long does a private Securonix batch take?
Typically three to four days. Architecture, ingestion and context take two days; detection engineering, investigation and content lifecycle take the rest. Teams onboarding a new deployment often extend it to five.
What lab environment do we need?
Attendees work in your tenant where one exists, otherwise a guided sample environment plus their own free-tier cloud account for generating realistic log sources. We deliberately do not hand out temporary sandboxes, because the environment they build is the one they keep.
What size are batches?
Private corporate batches run 8 to 30 engineers. Public Live & Interactive cohorts are capped at 10 so everyone gets time with the trainer.
Do attendees get a certificate?
Yes — every attendee receives a completion certificate, verifiable at devopsschool.com/certificates. Corporate batches also receive an attendance and assessment report.
What is your refund position?
If we cancel or postpone a cohort, you receive a full refund within 15 days. There is no general money-back guarantee, and GST and gateway fees are not refunded.

Still deciding?

Tell us the team, the stack and the timeline. You'll get a straight answer, not a sales sequence.

Talk to an advisor
# ready when you are

Book a Securonix trainer — or ask a question first.

  • No spam, no drip sequence
  • Syllabus in 60 seconds
  • A human reply within one business day

Prefer to call or email?

More ways to reach us on the contact page.

Talk to an advisorRequest a quote