MS Sentinal Engineer/SME

MS Sentinal Engineer/SME

6 month CTH

Remote

TOP SKILLS REQUIRED

TOP SKILLS REQUIRED:

Expert-level proficiency in Microsoft Sentinel

Operating in a FedRAMP environment

Design and implement – 

Analytics rules and detections

Log parsing and normalization

JOB SUMMARY 

As a Senior Cybersecurity Operations Engineer, you will play a key role in leading security operations by leveraging Microsoft Sentinel as the central platform for detection, investigation, and response. You will act as a lead for high-severity incidents, driving end-to-end triage, root cause analysis, and continuous improvement of detection capabilities. You will design and optimize detection use cases, lead proactive threat hunting initiatives, and enhance automation to improve response efficiency.

ESSENTIAL FUNCTIONS 

·                Lead triage and response for incidents and leading incident response efforts and coordination across technical teams during major security events

·       Drive root cause analysis (RCA) for critical incidents and translate findings into improvements across detection engineering, logging strategy, and response workflows

·       Own the log onboarding strategy and architecture for Microsoft Sentinel, ensuring comprehensive visibility across cloud, on-premises, and integrations

·       Lead integration of new data sources into Sentinel, including defining onboarding standards, data mapping, normalization, and validation of log quality

·       Identify and remediate logging gaps across the enterprise, partnering with engineering, cloud, and application teams to improve telemetry coverage

·       Establish and enforce best practices for log ingestion, retention, and cost optimization within Azure Sentinel

·       Design, develop, and continuously improve detection use cases and analytics rules, aligned to MITRE ATT&CK and evolving threat landscape

·       Own SIEM tuning strategy, reducing noise while ensuring high-confidence, high-fidelity detections

·       Lead proactive threat hunting initiatives using KQL and integrated threat intelligence, uncovering advanced or previously undetected threats

·       Architect and oversee Sentinel automation (playbooks, Logic Apps) to improve response efficiency and consistency

·       Develop and maintain advanced dashboards, workbooks, and reporting to provide actionable security insights to stakeholders

·       Mentor and coach junior and mid-level SOC analysts, setting standards for investigations, KQL usage, and operational excellence

·       Collaborate cross-functionally with cloud, DevOps, identity, and infrastructure teams to embed security visibility and detection into system design

·       Own and continuously improve SOC documentation, including SOPs, playbooks, and onboarding standards for new data sources and detections

EDUCATIONAL/SKILL/EXPERIENCE REQUIREMENTS 

Education/Experience 

·                Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field 

·       Equivalent combination of education and related experience 

·       5 years of experience in a Security Operations Center (SOC), Incident Response, Azure Cloud Security

Required Skills and Knowledge

·                Extensive SOC experience (L3/Senior/Principal level), serving as an escalation point for complex and high-severity incidents

·       Expert-level proficiency in Microsoft Sentinel (Azure SIEM), with deep expertise in log ingestion, integration, data lifecycle management, and incident investigation.

·       Strong expertise in log normalization, parsing, and data quality management, ensuring high-fidelity detections

·       Demonstrated ability to optimize SIEM performance, reducing noise while improving detection accuracy and coverage

·       Experience with automation and orchestration, including Sentinel playbooks and Logic Apps to enhance response efficiency

·       Deep experience in detection engineering, including designing, implementing, and tuning analytics aligned to MITRE ATT&CK

·       Advanced KQL expertise for large-scale data analysis, threat hunting, and detection development

·       Expertise in managing and utilizing a wide range of security tools, including Next Generation Firewall, IDS/IPS, EDR, AV, MS Defender Suite, Internet Proxy, other Cloud Security Tools, etc.

·       Strong knowledge of cloud and enterprise security technologies, including Microsoft Defender suite, identity security (Entra ID), EDR/XDR, firewalls, and cloud-native controls

·       Proven leadership in threat hunting and incident response, including RCA and continuous improvement of detection and response capabilities

·       Strong communication and stakeholder engagement skills, with the ability to influence technical and non-technical teams

·       Demonstrated mentorship of SOC analysts, driving operational maturity

·       Relevant certifications (SC-200, AZ-500, CySA+) preferred

·       Strong analytical and problem-solving skills, with the ability to operate effectively in a fast-paced environment

·       Commitment to continuous learning and staying current with evolving threats and technologies

Qual Call Notes:

Role Overview: Azure Sentinel / Azure SIEM Expert

This role is a hands-on Azure Sentinel expert responsible for leading a greenfield Sentinel build and expansion within an Azure cloud environment. Sentinel is already deployed, but this individual will drive the core buildout, integration, and operational maturity of the platform.

They will function as the technical driver—not a project manager—and are expected to come in with strong, real-world Sentinel expertise.


Core Responsibilities

·                Lead the initial buildout and deployment of Azure Sentinel

  • Design and implement:

o        Analytics rules and detections

  • Log parsing and normalization
  • Log source ingestion and integrations
  • Workbooks and dashboards
  • Logic Apps / automation and response workflows
  • Bring the Sentinel environment to an operational, customer-ready state
  • Support incident response activities
  • Participate in an on-call rotation
  • Continue to expand and mature the environment over time
  • Help upskill internal team members as the platform grows

Environment & Technology

·                Azure cloud (overall strong Azure experience required)

  • Azure Sentinel (SIEM) – deep, hands-on expertise required
  • IAM and Network Operations exposure
  • Operating in a FedRAMP environment

o        Team access is limited

  • Strong Microsoft support and partnership is in place

Team & Org Context

·                Role sits within Security, aligned to:

o        IAM

  • Network Operations
  • Colin is the CISO
  • Approximately 50% of the team reporting up to Colin is under Nithin
  • This role will initially be a single resource
  • Additional headcount planned:

o        Planning begins October

  • More HC expected early 2027

Delivery Goals & Timeline

·                Get the Sentinel environment fully built and production-ready

  • Hand off a stable, operational environment to the product team
  • First customer live early next year

Expectations

·                This person must join as a Sentinel subject-matter expert

  • They are not responsible for project management
  • Heavy focus on:

o        Technical execution

  • Initial log integrations
  • Operational readiness
  • Acts as the primary owner and driver of Sentinel from a technical standpoint
  • Works closely with Microsoft but owns the outcomes

Additional Notes

·                Sentinel is “greenfield” in terms of how it’s being positioned to candidates

  • On-call support will be required
  • Conversion salary details TBD

Please share with us your resume at resume@americantekresources.com