6 часов назад
Security Engineer ll – Microsoft Sentinel SIEM
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Engineer ll – Microsoft Sentinel SIEM (Microsoft Sentinel/Defender XDR): Administering and optimizing multi-tenant Microsoft security environments, onboarding telemetry, tuning KQL detections, and integrating SOAR automation with an accent on detection engineering, MDR operations, and platform reliability. Focus on mapping use cases to MITRE ATT&CK, investigating Tier 2 alerts, building Azure Logic Apps response workflows, and improving data quality and cost efficiency across managed services.
Location: Bengaluru, Karnataka, India. Hybrid work model with 2–3 days in the office. Platform coverage includes Eastern Time business hours.
Company
provides identity and access management, exposure management, risk programs, and managed detection and response services supported by its Meridian entity fabric and AI-augmented security operations.
What you will do
- Administer and maintain Microsoft Sentinel and Defender XDR across multiple managed client tenants.
- Onboard security data sources, validating connectivity, parsing, normalization, data quality, and entity mapping.
- Develop and tune Sentinel detection rules with KQL, including Scheduled, NRT, and Fusion analytics.
- Map detection use cases to MITRE ATT&CK and build reusable threat-hunting, dashboard, workbook, and reporting libraries.
- Monitor alerts and provide Tier 2 investigation and escalation support for MDR and SOC teams.
- Build Azure Logic Apps SOAR workflows for actions such as device isolation, user disablement, IP blocking, and ticket creation.
Requirements
- Diploma or bachelor’s degree in computer science, cybersecurity, information technology, or a related field, or equivalent practical experience.
- 3–5 years of experience in cybersecurity, SOC, security engineering, or related roles, including at least 2 years of hands-on Microsoft Sentinel experience.
- Hands-on experience with Microsoft Sentinel, Microsoft Defender XDR, Azure Log Analytics, and KQL.
- Experience in an MSSP, MDR, or customer-facing security environment with multi-tenant Azure environments; Azure Lighthouse experience is required.
- Knowledge of Windows and Linux logs, Entra ID, networking, authentication and authorization, security telemetry, MITRE ATT&CK, and MDR/SOC workflows.
- Experience with Azure Logic Apps, REST APIs, and PowerShell or Python scripting, plus strong documentation skills.
Nice to have
- SC-200, AZ-500, SC-100, Security+, or Microsoft Defender certifications.
Culture & Benefits
- Medical insurance covering employees and dependents.
- Life insurance and a retirement match program.
- Maternity and paternity leave, paid time off, sick and casual leave.
- Bereavement and volunteer time.
- Professional development reimbursement and access to LinkedIn Learning courses.
- Mobile phone reimbursement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Lead Information Security Analyst (Cybersecurity)
7 дней назад
IT Security Analyst - Identity & Access Management (IAM)
18 часов назад
Senior Cybersecurity Incident Responder
6 дней назад
IT Security Analyst (IAM)
4 дня назад
Data Protection Analyst (Cybersecurity)
7 часов назад