14 дней назад
Sentinel Engineer (Microsoft Sentinel)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sentinel Engineer (Microsoft Sentinel): Designing, deploying, and managing Microsoft Sentinel environments for managed-services clients with an accent on ingestion architectures, data connectors, workspace design, and detection logic. Focus on building SOAR playbooks with Logic Apps, resolving platform issues, analyzing security use cases, and supporting cross-tenant enterprise environments.
Location: Remote, Brentwood, Tennessee, United States
Company
is a technology services company delivering professional and managed services across cloud infrastructure, networking, cybersecurity, data and AI, automation, observability, and enterprise service management.
What you will do
- Deliver Microsoft Sentinel projects by defining system requirements, solution designs, standards, and implementation methodologies.
- Architect Sentinel ingestion and integration environments, including data connectors, workspace design, and cross-tenant or Lighthouse configurations.
- Translate business requirements into technical solutions, identify gaps, and improve Sentinel-related workflows.
- Identify automation opportunities and develop SOAR playbooks with Logic Apps.
- Act as an escalation point for customers and internal teams, process tickets, and resolve platform issues.
- Analyze security use cases, support cybersecurity initiatives, track work, and maintain business documentation.
Requirements
- At least 5 years of experience in information security.
- Experience deploying and managing Microsoft Sentinel, including workspace architecture, data connectors, and content management.
- Required experience with KQL and writing Sentinel analytics rules, hunting queries, or comparable detection logic.
- Strong foundations in networking, security best practices, systems administration, and information security programs.
- Strong communication, problem-solving, critical-thinking, diagnostic, organizational, and accountability skills.
- Ability to work in project teams, complete individual tasks on time, and coordinate events or meetings.
Nice to have
- Python or other scripting-language experience.
- Familiarity with Defender XDR, Entra ID, and Microsoft 365 Defender.
Culture & Benefits
- Remote work arrangement.
- Client-facing work within managed cybersecurity services.
- Continuous learning and staying current with emerging security threats.
- Travel may be required.
- Inclusive workplace with accommodations available throughout the interview process and beyond.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →