6 часов назад
Senior Security Engineer (Microsoft Sentinel SIEM)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer (Microsoft Sentinel SIEM): Managing and advancing Microsoft Sentinel and Defender XDR platforms for managed client environments with an accent on detection engineering, telemetry ingestion, and security automation. Focus on designing KQL detections, building Azure Logic Apps SOAR workflows, resolving complex multi-tenant integration issues, and improving alert fidelity.
Location: Bengaluru, Karnataka, India; hybrid work with 2–3 days in the office
Company
provides managed cybersecurity services, including identity and access management, exposure management, managed detection and response, and security platforms.
What you will do
- Act as the subject matter expert for Microsoft Sentinel and Microsoft Defender XDR across managed client environments.
- Administer, configure, and manage the lifecycle of Sentinel and Defender XDR platforms.
- Lead data-source onboarding, integrations, parsing, normalization, telemetry visibility, and platform health management.
- Design and tune KQL-based detections, analytics rules, threat-hunting use cases, and MITRE ATT&CK mappings.
- Architect Azure Logic Apps SOAR automation and develop dashboards, workbooks, runbooks, SOPs, and technical documentation.
- Resolve complex ingestion and integration issues, mentor junior engineers, and contribute to platform standardization and service improvements.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent experience.
- 5+ years of experience in security operations, SOC, or security engineering, including at least 3 years of hands-on Microsoft Sentinel experience.
- Expertise with Microsoft Defender XDR and experience in MSSP, MDR, or customer-facing security environments.
- Experience supporting multi-tenant environments with Azure Lighthouse.
- Proficiency in KQL, detection engineering, threat hunting, Azure Logic Apps, REST APIs, and PowerShell or Python scripting.
- Experience with Windows and Linux logs, Entra ID, networking, authentication technologies, MITRE ATT&CK, troubleshooting, documentation, and SOC operations.
Nice to have
- Certifications such as SC-200, AZ-500, SC-100, CompTIA Security+, or Microsoft Defender certifications.
Culture & Benefits
- Medical insurance covering employees and dependents.
- Life insurance and a retirement match program.
- Maternity and paternity leave, paid time off, sick and casual leave.
- Bereavement and volunteer time.
- Professional development reimbursement and access to LinkedIn Learning courses.
- Mobile phone reimbursement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Lead Information Security Analyst (Cybersecurity)
18 часов назад
Senior Cybersecurity Incident Responder
8 часов назад
Principal IS Analyst-IT Security
7 дней назад
IT Security Analyst - Identity & Access Management (IAM)
6 часов назад
IT Security Analyst (Cybersecurity)
MoonPay
3 дня назад