Full Job Description
Job Summary
The Senior Microsoft Sentinel Engineer / Architect will serve as the technical engineering lead for designing, implementing, optimizing, and automating enterprise security solutions across infrastructure, applications, identities, and data. The role focuses on Microsoft Sentinel, KQL, Azure security, Microsoft Defender, Microsoft Purview, SIEM/SOAR, detection engineering, threat hunting, and security automation. The engineer will collaborate with Security Operations, Cloud Engineering, Infrastructure, DevSecOps, and IT teams to improve security visibility, detection and response capabilities, and automation across a complex, multi-vendor environment.
Key Responsibilities
• Serve as the senior technical lead and architect for Microsoft Sentinel, including workspace architecture, deployment, configuration, data onboarding, normalization, analytics, monitoring, and optimization.
• Design and develop advanced Microsoft Sentinel detection capabilities using KQL, including custom analytics rules, scheduled queries, threat hunting queries, workbooks, dashboards, and security content.
• Develop and maintain SOAR capabilities using Sentinel automation rules, Logic Apps, Azure Functions, and other automation technologies.
• Integrate Sentinel with Microsoft and third-party security platforms using REST APIs, webhooks, connectors, custom integrations, and automated workflows.
• Engineer security solutions across Microsoft Azure, including Defender for Cloud, Azure Policy, Entra ID, Conditional Access, Key Vault, network security controls, logging, monitoring, and identity security.
• Implement and administer Microsoft Purview, including Data Loss Prevention (DLP), sensitivity labels, information protection, insider risk management, auditing, and compliance-related security controls.
• Identify manual and repetitive security processes and design end-to-end automation to improve operational efficiency, consistency, scalability, and response times.
• Develop and maintain security infrastructure and content using Infrastructure as Code, including Terraform, Bicep, or ARM templates.
• Implement security engineering practices through Git, Azure DevOps, or GitHub, including version control, peer review, automated testing, and CI/CD pipelines.
• Support security incident investigations, threat hunting, intrusion analysis, vulnerability management, and incident response across cloud, network, endpoint, identity, and application environments.
• Review security controls and monitoring capabilities to identify gaps, improve detection coverage, reduce false positives, and strengthen protection against advanced cyber threats.
• Establish engineering standards and best practices for SIEM/SOAR architecture, detection engineering, security automation, logging, and cloud security.
• Collaborate with Security Operations teams to improve incident triage, investigation workflows, response automation, and security operations metrics.
• Provide technical guidance and mentorship to security engineers and other technical teams.
Required Qualifications
• 10+ years of experience as a Cloud Security Engineer, Information Security Engineer, Security Architect, or DevSecOps Engineer.
• 5+ years of hands-on Microsoft Sentinel engineering and architecture experience.
• Experience with Sentinel workspace deployment and architecture, data source onboarding and normalization, custom analytics rules, KQL development, threat hunting, workbooks, dashboards, automation rules, and SOAR playbooks.
• Advanced proficiency with Kusto Query Language (KQL) for detection engineering, threat hunting, investigation, analytics, and workbook development.
• Strong hands-on experience securing Microsoft Azure environments, including Microsoft Defender for Cloud, Azure Policy, Microsoft Entra ID, Conditional Access, Azure networking and security controls, Key Vault, and Azure logging and monitoring.
• Hands-on experience implementing and administering Microsoft Purview, including DLP policies, sensitivity labels, Information Protection, Insider Risk Management, and audit and compliance capabilities.
• Demonstrated experience identifying manual, repeatable security processes and automating them end to end across Microsoft and non-Microsoft security platforms.
• Experience integrating security platforms through REST APIs, webhooks, connectors, and custom automation.
• Strong scripting and development skills with Python and PowerShell.
• Hands-on experience with Azure Logic Apps and Azure Functions.
• Experience with Infrastructure as Code, including Terraform, Bicep, and/or ARM.
• Experience managing security automation and content through Git, Azure DevOps, GitHub, and CI/CD pipelines.
• 5+ years of experience with network, cloud, and computer system security, including user access controls, RBAC, SSO, file permissions, firewall policies, audit logging, and network security controls.
• 5+ years of experience with enterprise security technologies, including SIEM/SOAR, firewalls, intrusion detection/prevention systems, endpoint protection, web application firewalls, vulnerability scanning, data loss prevention, log management, and content filtering.
• 5+ years of experience developing and deploying security solutions designed to defend against advanced cyber threats.
• 5+ years of experience reviewing, monitoring, and troubleshooting security systems to ensure security controls are operating effectively.
• 5+ years of experience investigating security incidents and intrusions, conducting technical investigations, performing threat analysis, and supporting incident response.
Preferred Qualifications
• Microsoft security certifications such as SC-200, SC-100, AZ-500, or related certifications.
• Experience with Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, and Defender for Office 365.
• Experience integrating Microsoft Sentinel with third-party SIEM, SOAR, EDR, IAM, vulnerability management, and network security platforms.
• Experience with MITRE ATT&CK, threat modeling, detection-as-code, and security content lifecycle management.
• Experience operating security platforms in large-scale enterprise or regulated environments.
• Strong understanding of Zero Trust architecture, identity security, cloud security, and modern SOC operations.
• Strong communication skills with the ability to translate security requirements into scalable technical solutions.
Certifications
• Microsoft security certifications such as SC-200, SC-100, AZ-500, or related certifications.