Microsoft Sentinel SIEM Consultant

Job Description

Other Jobs You May Be Interested In

Design, deploy, and manage the Microsoft Sentinel SIEM platform to monitor and analyze security events and logs. Configure and customize SIEM rules, alerts, and reports

The primary responsibilities for this role will be the development, maintenance and enforcement of the Azure Sentinel technology and related operational processes in order to adequately protect assets and customer data as well as providing an escalation point for SOC to consult and trust in the candidate’s technical knowledge base. Azure Sentinel Engineer is needed to develop and grow customer’s Azure environment and work with infrastructure and application teams.

Responsibilities

Logging and auditing cloud infrastructure with Azure Sentinel and orchestration efforts

Leveraging security infrastructure to build automated workflows

Build high confidence correlation using automated workflows based on various sources and use cases

Leverage Threat Intelligence feeds in Sentinel analytics and SOAR

Integrating security logs into Azure Log Analytics Workspace

Develop incident response use cases using Logic Apps in Azure

Developing remediation recommendations for findings where automated actions have not yet been applied

Working collaboratively with team members and stakeholders, and clearly and proactively communicating work status, key issues and risks to management

Continuous assessment of data coverage and areas for improving Azure Sentinel

Create process documentation related to Azure Sentinel