We’re looking for an experienced Microsoft Sentinel Security Engineer to design, implement, and manage Microsoft Sentinel environments for enterprise security operations. The ideal candidate will have strong hands-on experience in Microsoft Sentinel, SIEM, threat detection, incident response, and automation within the Microsoft Security ecosystem.
Responsibilities
- Design, configure, and maintain Microsoft Sentinel environments.
- Configure and manage data connectors, analytics rules, playbooks (Logic Apps), workbooks, and incident management workflows.
- Monitor security alerts, investigate incidents, perform root cause analysis, and support remediation activities.
- Tune detection rules and analytics to reduce false positives and improve threat detection.
- Integrate Microsoft Sentinel with enterprise security and IAM platforms such as Microsoft Defender, Azure Monitor, Azure AD, Saviynt, Okta, Ping Identity, and CyberArk.
- Develop dashboards, KQL queries, PowerShell scripts, and automation workflows to enhance security operations.
- Document Sentinel configurations, operational runbooks, and solution architecture.
- Collaborate with clients, architects, and cross-functional cyber security teams to deliver scalable and secure SIEM solutions.
Requirements
- Minimum 5 years of experience in Cyber Security, SIEM, or Security Operations.
- Strong hands-on expertise with Microsoft Sentinel implementation, configuration, and administration.
- Experience with Microsoft Security technologies including Microsoft Defender, Azure Security Center, Azure Monitor, and Log Analytics.
- Strong understanding of SIEM concepts, threat detection, incident response, log analysis, and security monitoring.
- Hands-on experience with KQL, PowerShell, Azure CLI, and security automation.
- Knowledge of Identity and Access Management (IAM) concepts and integration with platforms such as Saviynt, Okta, Ping Identity, Azure AD (Microsoft Entra ID), and CyberArk.
- Strong analytical, troubleshooting, documentation, and communication skills.
Nice to have
- Microsoft security certifications such as SC-200, SC-300, AZ-500, or equivalent are an added advantage.
Benefits
- Work with a talented and collaborative Cyber Security & IAM team.
- Opportunity to work on enterprise-scale Microsoft Security and SIEM implementations.
- Exposure to cutting-edge cloud security, automation, and Identity Security technologies.
- Continuous learning, certification support, and career growth opportunities.
Additional details
- Location: Bengaluru (On-site)
- Availability: Immediate Joiners Preferred