
Security Engineer
Posted 10 hours ago

Posted 10 hours ago
This is a fully remote position, open to applicants in Ukraine.
• Manage the comprehensive onboarding process of client Microsoft Sentinel environments into the MSSP service.
• Configure Sentinel workspaces, content solutions, data connectors, analytics rules, automation rules, watchlists, and workbooks.
• Conduct technical discovery sessions that explore log sources, connectivity, data volumes, retention, dependencies, and priorities.
• Integrate Microsoft, third-party, cloud, network, identity, and application log sources utilizing Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF, and custom connectors.
• Design and execute data filtering and transformation strategies to enhance signal quality and manage ingestion costs effectively.
• Validate the ingestion process, parsing, field mapping, timestamps, health, and coverage; troubleshoot issues related to sources, collectors, network, and Azure.
• Optimize analytics rules, alert logic, and incident generation in collaboration with SOC and detection engineering teams.
• Onboard and integrate Microsoft Defender XDR workloads, encompassing Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.
• Generate high-level designs, implementation plans, configuration records, testing evidence, operational runbooks, and handover documentation.
• Collaborate with clients, project managers, architects, SOC analysts, and service teams regarding dependencies, risks, actions, and service transition readiness.
• Implement engineering standards, peer reviews, and change control; enhance onboarding templates, technical patterns, and internal procedures.
• Provide support for troubleshooting and remediation during onboarding and initial support phases.
• Occasionally travel as required for client delivery.
• Oversee assigned onboarding activities from discovery and design through implementation, testing, documentation, and handover.
• Report to the Head of Cloud Security & Microsoft Security Services.
• Hands-on experience in deploying, configuring, or supporting Microsoft Sentinel in production or customer environments.
• Practical knowledge of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection patterns.
• Proficient in Kusto Query Language.
• Experience in onboarding and troubleshooting log sources across Microsoft 365, Azure, endpoints, identity, network, security, and third-party platforms.
• Understanding of ingestion filtering, data transformation, parsing, normalization, retention, and security telemetry costs.
• Experience in creating technical designs and delivery documentation, including HLDs, implementation plans, test records, and operational handover materials.
• Working knowledge of Microsoft Defender XDR and its integration with Microsoft Sentinel.
• Familiarity with SIEM operations, detection engineering, incident workflows, and managed security service requirements.
• Strong troubleshooting abilities across Azure, APIs, identity, networking, and data collection components.
• Effective written and verbal communication skills with both technical and non-technical client stakeholders.
• Capability to manage assigned tasks independently while collaborating with project, architecture, SOC, and service teams.
• Experience in working for an MSSP, MDR provider, Security Operations Centre, or security-focused professional services team is preferred.
• Experience with custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is preferred.
• Familiarity with DevOps pipelines, source control, detection as code, infrastructure as code, and automation is preferred.
• Knowledge of Microsoft Sentinel repositories, content management, and multi-customer deployment patterns is preferred.
• Experience in integrating Microsoft security services across tenants, subscriptions, or delegated administration models is preferred.
• Familiarity with MITRE ATT&CK is preferred.
• Microsoft Certified: Security Operations Analyst Associate (SC-200) is preferred.
• Microsoft Certified: Azure Security Engineer Associate (AZ-500/SC-500) is preferred.
• Microsoft Certified: Cybersecurity Architect Expert (SC-100) is preferred.
• Relevant Microsoft Applied Skills or other pertinent security/cloud certifications are advantageous but not mandatory.
• Opportunities for learning, development, and career progression.
• Training and certification prospects in Microsoft security technologies.
• Support from a seasoned team.
Rackspace Technology
Efficient Computer
Presidio
Presidio
Get handpicked remote jobs straight to your inbox weekly.