We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement, optimize, and manage Microsoft Sentinel and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection, incident response, security automation, cloud security, and compliance across enterprise Azure environments.
Roles and Responsibilities
- Design, implement, configure, and manage Microsoft Sentinel SIEM/SOAR solutions.
- Integrate security data sources into Azure Log Analytics, including Syslog, CEF, APIs, and threat intelligence feeds.
- Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards.
- Develop automated security response workflows using Azure Logic Apps and Microsoft Copilot for Security.
- Perform threat hunting, incident investigation, detection engineering, and response activities in collaboration with SOC teams.
- Implement and manage Azure security controls aligned with Zero Trust principles.
- Configure and secure enterprise Azure environments, including identity, access, monitoring, and security services.
- Assess vulnerabilities, analyze attacker TTPs, and support remediation and security improvement initiatives.
- Integrate and manage Microsoft Defender XDR, including Defender for Endpoint, Office 365, Identity, and Cloud Apps.
- Support cloud security governance, compliance, risk assessments, and audit activities.
- Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and cloud security initiatives.
- Develop security standards, operational procedures, and best practices for Sentinel and Azure security services.
- Collaborate with Security Operations, Cloud Engineering, Identity, Application Security, and Governance teams.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- 5+ years of cybersecurity experience, including strong hands-on experience with Microsoft Sentinel engineering and administration.
- Strong expertise in:
- Microsoft Sentinel
- Azure Log Analytics
- Kusto Query Language (KQL)
- Azure Logic Apps
- Microsoft Defender XDR
- Azure Security and Identity Services
- Microsoft Entra ID
- Privileged Identity Management (PIM)
- Conditional Access
- Security monitoring and incident response
- CI/CD security and application security scanning
- Strong understanding of SIEM/SOAR, threat detection, threat hunting, incident response, and security automation.
- Experience implementing security controls in enterprise Azure environments.
- Strong knowledge of Zero Trust architecture and cloud security best practices.
Preferred Qualifications
- Experience with Azure Government / Government Cloud environments.
- Experience with FISMA, FedRAMP, and NIST security and compliance frameworks.
- Relevant certifications such as CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Cybersecurity Architect Expert.
- Experience working with security auditors, compliance teams, and executive stakeholders.