Key Responsibilities
As a Senior Microsoft Sentinel SIEM Engineer / Administrator, you will:
- Design, administer, and optimize Microsoft Sentinel and supporting Azure security services.
- Integrate multiple security technologies and participating entities into a centralized SIEM platform.
- Develop and maintain analytics rules, detection use cases, hunting queries, dashboards, workbooks, and SOAR playbooks.
- Configure and manage log ingestion using APIs, Azure Monitor Agent, Event Hubs, Syslog, CEF, and custom connectors.
- Monitor platform health, data ingestion, connector performance, and overall SIEM operations.
- Develop Kusto Query Language (KQL) queries for advanced detection engineering and threat hunting.
- Integrate Microsoft Sentinel with EDR, XDR, SOAR, threat intelligence, and other security platforms.
- Support SOC analysts with incident investigations, automation, and continuous platform improvements.
What We're Looking For
Required Qualifications:
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- Minimum 3 years of hands-on experience administering Microsoft Sentinel SIEM.
- Strong expertise with Microsoft Azure, Log Analytics, Azure Monitor, Azure Functions, Logic Apps, Event Hubs, and Microsoft Entra ID.
- Advanced proficiency in Kusto Query Language (KQL).
- Experience with SIEM integrations, detection engineering, threat hunting, automation, and security operations.
- Strong knowledge of MITRE ATT&CK, API integrations, Syslog, CEF, REST APIs, and security monitoring best practices.
Preferred Qualifications
- Microsoft Certified: Security Operations Analyst Associate
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft Certified: Cybersecurity Architect Expert
- Experience with Microsoft Defender XDR, Defender for Cloud, Defender for Endpoint, CI/CD, Infrastructure as Code, and scripting (Python, PowerShell, Bash).
Why Join Us?
- Work on large-scale enterprise cybersecurity initiatives.
- Collaborate with experienced SOC, Threat Intelligence, and Cloud Security teams.
- Design and implement advanced SIEM, detection engineering, and security automation solutions.
- Make a direct impact in strengthening cyber resilience and security operations.