Security Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in Lithuania.

📋 Description

• Oversee the comprehensive onboarding of client Microsoft Sentinel environments into the MSSP service.

• Set up Sentinel workspaces, content solutions, data connectors, analytics rules, automation rules, watchlists, and workbooks.

• Conduct technical discovery sessions that include log sources, connectivity, data volumes, retention, dependencies, and priorities.

• Integrate Microsoft, third-party, cloud, network, identity, and application log sources utilizing Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF, and custom connectors.

• Develop and apply data filtering and transformation strategies to enhance signal quality and manage ingestion costs effectively.

• Verify ingestion processes, parsing, field mapping, timestamps, health checks, and coverage, while troubleshooting issues across source systems and Azure services.

• Refine analytics rules, alert logic, and incident generation in collaboration with SOC and detection engineering teams.

• Integrate and onboard Microsoft Defender XDR workloads, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.

• Create high-level designs, implementation plans, configuration records, testing evidence, operational runbooks, and handover documentation.

• Collaborate with clients, project managers, architects, SOC analysts, and service teams regarding dependencies, risks, actions, and service transition readiness.

• Implement engineering standards, conduct peer reviews and change control, and enhance onboarding templates and internal procedures.

• Assist with troubleshooting and remediation during the onboarding phase and early-life support.

• Travel occasionally for client delivery needs.


⛳️ Requirements

• Practical experience in deploying, configuring, or supporting Microsoft Sentinel within production or customer environments.

• Solid understanding of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection methodologies.

• Proficient in Kusto Query Language for data validation, troubleshooting, investigation, and detection tuning.

• Experience in onboarding and resolving issues related to log sources across Microsoft 365, Azure, endpoints, identity, network, security, and third-party platforms.

• Knowledge of ingestion filtering, data transformation, parsing, normalization, retention, and the cost implications of security telemetry.

• Experience in producing technical designs and delivery documentation, including high-level designs (HLDs), implementation plans, test records, and operational handover materials.

• Familiarity with Microsoft Defender XDR and its workload integration with Microsoft Sentinel.

• Understanding of SIEM operations, detection engineering principles, incident workflows, and managed security service requirements.

• Strong troubleshooting capabilities across Azure, APIs, identity, networking, and data collection components.

• Excellent written and verbal communication skills to engage with both technical and non-technical client stakeholders.

• Ability to independently manage assigned tasks while collaborating with project, architecture, SOC, and service teams.

• Experience in working with an MSSP, MDR provider, Security Operations Centre, or security-focused professional services team is preferred.

• Knowledge of custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is desirable.

• Familiarity with DevOps pipelines and source control for Microsoft Sentinel content, configuration, and deployment is advantageous.

• Understanding of detection as code, infrastructure as code, and automation technologies such as Bicep, ARM templates, Terraform, PowerShell, Azure CLI, Logic Apps, or APIs is beneficial.

• Familiarity with Microsoft Sentinel repositories, content management, and repeatable multi-customer deployment patterns is a plus.

• Experience integrating Microsoft security services across tenants, subscriptions, or delegated administration models like Azure Lighthouse is advantageous.

• Knowledge of MITRE ATT&CK framework is preferred.

• Microsoft security certifications such as SC-200, AZ-500/SC-500, or SC-100 are desirable but not mandatory.


🏝️ Benefits

• Opportunities for learning, development, and career progression.

• Training and certification options available across Microsoft security technologies.

• Support from a knowledgeable and experienced team.

• Occasional travel to assist with client delivery.

People also viewed

Integrity3601 day ago

Security Engineer

UA flagUkraine OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Rackspace Technology1 day ago

Security Engineer IV

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$119.6k – $175.4k/year
ApplyView job
Efficient Computer1 day ago

Director of Information Security

US flagCalifornia, +2 more statesFull-timeCybersecurity / Security Engineer$180k – $230k/year
ApplyView job
Presidio1 day ago

Senior Director, Cybersecurity Advisory Services

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Presidio1 day ago

Senior Director, Cybersecurity Advisory Services

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
XBOX1 day ago

Senior Security Engineer

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$102.8k – $190.2k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers