Job Summary: Azure Sentinel Security Engineer
- Monitor and audit cloud infrastructure using Azure Sentinel for logging and auditing requirements.
- Develop and maintain automated workflows to streamline security operations.
- Integrate threat intelligence feeds into Sentinel analytics and SOAR systems.
- Create incident response use cases and provide remediation recommendations.
- Integrate security logs into Azure Log Analytics Workspace for centralized monitoring.
- Work collaboratively with team members and stakeholders to ensure effective communication and project success.
- Maintain comprehensive documentation related to Azure Sentinel configurations and operational processes.
- Demonstrate expertise in Azure Sentinel Microsoft Defender and other Microsoft security tools.
- Utilize scripting languages such as Python or PowerShell for automation and integration tasks.
- Possess strong knowledge of Azure security services and governance best practices.
- Create custom Sentinel Playbooks and dashboards for effective platform monitoring.
- Ingest various types of Syslog data and network device logs via APIs and configure appropriate Data Collection Rules (DCRs).
- Onboard security devices develop SIEM content and use Kusto Query Language (KQL) for data analysis.
- Develop and maintain custom scripts and connectors for integrating various devices into Sentinel.
- Create and maintain new SOC Run Books to support security operations.
- Bring experience with other SIEM tools such as ArcSight QRadar or Splunk.
- Hold relevant certifications such as Microsoft Certified: Azure Security Engineer Associate or equivalent.