Security Engineer

Posted 10 hours ago

This is a fully remote position, open to applicants in Ukraine.

📋 Description

• Manage the comprehensive onboarding process of client Microsoft Sentinel environments into the MSSP service.

• Configure Sentinel workspaces, content solutions, data connectors, analytics rules, automation rules, watchlists, and workbooks.

• Conduct technical discovery sessions that explore log sources, connectivity, data volumes, retention, dependencies, and priorities.

• Integrate Microsoft, third-party, cloud, network, identity, and application log sources utilizing Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF, and custom connectors.

• Design and execute data filtering and transformation strategies to enhance signal quality and manage ingestion costs effectively.

• Validate the ingestion process, parsing, field mapping, timestamps, health, and coverage; troubleshoot issues related to sources, collectors, network, and Azure.

• Optimize analytics rules, alert logic, and incident generation in collaboration with SOC and detection engineering teams.

• Onboard and integrate Microsoft Defender XDR workloads, encompassing Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.

• Generate high-level designs, implementation plans, configuration records, testing evidence, operational runbooks, and handover documentation.

• Collaborate with clients, project managers, architects, SOC analysts, and service teams regarding dependencies, risks, actions, and service transition readiness.

• Implement engineering standards, peer reviews, and change control; enhance onboarding templates, technical patterns, and internal procedures.

• Provide support for troubleshooting and remediation during onboarding and initial support phases.

• Occasionally travel as required for client delivery.

• Oversee assigned onboarding activities from discovery and design through implementation, testing, documentation, and handover.

• Report to the Head of Cloud Security & Microsoft Security Services.


⛳️ Requirements

• Hands-on experience in deploying, configuring, or supporting Microsoft Sentinel in production or customer environments.

• Practical knowledge of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection patterns.

• Proficient in Kusto Query Language.

• Experience in onboarding and troubleshooting log sources across Microsoft 365, Azure, endpoints, identity, network, security, and third-party platforms.

• Understanding of ingestion filtering, data transformation, parsing, normalization, retention, and security telemetry costs.

• Experience in creating technical designs and delivery documentation, including HLDs, implementation plans, test records, and operational handover materials.

• Working knowledge of Microsoft Defender XDR and its integration with Microsoft Sentinel.

• Familiarity with SIEM operations, detection engineering, incident workflows, and managed security service requirements.

• Strong troubleshooting abilities across Azure, APIs, identity, networking, and data collection components.

• Effective written and verbal communication skills with both technical and non-technical client stakeholders.

• Capability to manage assigned tasks independently while collaborating with project, architecture, SOC, and service teams.

• Experience in working for an MSSP, MDR provider, Security Operations Centre, or security-focused professional services team is preferred.

• Experience with custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is preferred.

• Familiarity with DevOps pipelines, source control, detection as code, infrastructure as code, and automation is preferred.

• Knowledge of Microsoft Sentinel repositories, content management, and multi-customer deployment patterns is preferred.

• Experience in integrating Microsoft security services across tenants, subscriptions, or delegated administration models is preferred.

• Familiarity with MITRE ATT&CK is preferred.

• Microsoft Certified: Security Operations Analyst Associate (SC-200) is preferred.

• Microsoft Certified: Azure Security Engineer Associate (AZ-500/SC-500) is preferred.

• Microsoft Certified: Cybersecurity Architect Expert (SC-100) is preferred.

• Relevant Microsoft Applied Skills or other pertinent security/cloud certifications are advantageous but not mandatory.


🏝️ Benefits

• Opportunities for learning, development, and career progression.

• Training and certification prospects in Microsoft security technologies.

• Support from a seasoned team.

People also viewed

Rackspace Technology10 hours ago

Security Engineer IV

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$119.6k – $175.4k/year
ApplyView job
Efficient Computer11 hours ago

Director of Information Security

US flagCalifornia, +2 more statesFull-timeCybersecurity / Security Engineer$180k – $230k/year
ApplyView job
Presidio11 hours ago

Senior Director, Cybersecurity Advisory Services

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Presidio11 hours ago

Senior Director, Cybersecurity Advisory Services

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
XBOX11 hours ago

Senior Security Engineer

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$102.8k – $190.2k/year
ApplyView job
Localiza&Co11 hours ago

Senior Product Owner – Cyber Security

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers