
Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Lithuania.
• Oversee the comprehensive onboarding of client Microsoft Sentinel environments into the MSSP service.
• Set up Sentinel workspaces, content solutions, data connectors, analytics rules, automation rules, watchlists, and workbooks.
• Conduct technical discovery sessions that include log sources, connectivity, data volumes, retention, dependencies, and priorities.
• Integrate Microsoft, third-party, cloud, network, identity, and application log sources utilizing Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF, and custom connectors.
• Develop and apply data filtering and transformation strategies to enhance signal quality and manage ingestion costs effectively.
• Verify ingestion processes, parsing, field mapping, timestamps, health checks, and coverage, while troubleshooting issues across source systems and Azure services.
• Refine analytics rules, alert logic, and incident generation in collaboration with SOC and detection engineering teams.
• Integrate and onboard Microsoft Defender XDR workloads, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.
• Create high-level designs, implementation plans, configuration records, testing evidence, operational runbooks, and handover documentation.
• Collaborate with clients, project managers, architects, SOC analysts, and service teams regarding dependencies, risks, actions, and service transition readiness.
• Implement engineering standards, conduct peer reviews and change control, and enhance onboarding templates and internal procedures.
• Assist with troubleshooting and remediation during the onboarding phase and early-life support.
• Travel occasionally for client delivery needs.
• Practical experience in deploying, configuring, or supporting Microsoft Sentinel within production or customer environments.
• Solid understanding of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection methodologies.
• Proficient in Kusto Query Language for data validation, troubleshooting, investigation, and detection tuning.
• Experience in onboarding and resolving issues related to log sources across Microsoft 365, Azure, endpoints, identity, network, security, and third-party platforms.
• Knowledge of ingestion filtering, data transformation, parsing, normalization, retention, and the cost implications of security telemetry.
• Experience in producing technical designs and delivery documentation, including high-level designs (HLDs), implementation plans, test records, and operational handover materials.
• Familiarity with Microsoft Defender XDR and its workload integration with Microsoft Sentinel.
• Understanding of SIEM operations, detection engineering principles, incident workflows, and managed security service requirements.
• Strong troubleshooting capabilities across Azure, APIs, identity, networking, and data collection components.
• Excellent written and verbal communication skills to engage with both technical and non-technical client stakeholders.
• Ability to independently manage assigned tasks while collaborating with project, architecture, SOC, and service teams.
• Experience in working with an MSSP, MDR provider, Security Operations Centre, or security-focused professional services team is preferred.
• Knowledge of custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is desirable.
• Familiarity with DevOps pipelines and source control for Microsoft Sentinel content, configuration, and deployment is advantageous.
• Understanding of detection as code, infrastructure as code, and automation technologies such as Bicep, ARM templates, Terraform, PowerShell, Azure CLI, Logic Apps, or APIs is beneficial.
• Familiarity with Microsoft Sentinel repositories, content management, and repeatable multi-customer deployment patterns is a plus.
• Experience integrating Microsoft security services across tenants, subscriptions, or delegated administration models like Azure Lighthouse is advantageous.
• Knowledge of MITRE ATT&CK framework is preferred.
• Microsoft security certifications such as SC-200, AZ-500/SC-500, or SC-100 are desirable but not mandatory.
• Opportunities for learning, development, and career progression.
• Training and certification options available across Microsoft security technologies.
• Support from a knowledgeable and experienced team.
• Occasional travel to assist with client delivery.
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.