Microsoft Sentinel
2 days ago
We are seeking a skilled and motivated Microsoft Sentinel & Defender Engineer to join our Dedicated Defense team. In this role, you will help strengthen our security posture by deploying and managing Microsoft security technologies, focusing on threat detection, response, and automation. This is an excellent opportunity for someone passionate about cybersecurity and eager to work with cutting-edge Microsoft security solutions.
Key ResponsibilitiesDeploy and maintain Microsoft Sentinel for SIEM use cases, including log ingestion, data normalization, and incident correlation
Manage and optimize Microsoft Defender solutions (Endpoint, Identity, Cloud, M365) to ensure maximum protection and visibility
Develop custom KQL queries, detection rules, dashboards, and automation playbooks to enhance threat detection and response
Configure data connectors, analytics rules, and incident automation within Sentinel
Collaborate with threat analysts and incident response teams to investigate and remediate security alerts
Provide guidance on security best practices, threat hunting, and incident response using Microsoft tools
Continuously assess and improve security configurations, policies, and workflows
Bachelor's degree in computer science, Information Security, or equivalent experience
3+ years of experience in cybersecurity or SOC engineering roles
Hands-on experience with Microsoft Sentinel and Microsoft Defender suite
Strong understanding of SIEM concepts, threat detection, and incident response
Proficiency in Kusto Query Language (KQL) for building custom analytics and workbooks
Solid understanding of common network protocols, operating systems (Windows, Linux), cloud architectures (Azure), and security concepts (e.g., Zero Trust, defense-in-depth)
Familiarity with MITRE ATT&CK framework and security best practices
- Basic scripting skills (PowerShell or Python) for automation tasks
- Knowledge of Azure security services and cloud security principles.
Excellent communication skills and ability to work in customer-facing environments
Nice-to-Have
Experience integrating Sentinel with third-party tools (threat intel feeds, ticketing systems)
Exposure to cloud-native SIEM solutions and multi-cloud environments (AWS, GCP)
Understanding of NIST and other compliance frameworks
Private Health Insurance
Training & Development
Performance Bonus
Laptop
Phone-Mobile phone