Padmi

Security Engineer - Sentinel

IndiaPosted 3 months ago
CybersecurityMid-levelFull Time; Regular
Apply at Norwin Technologies

Opens the source posting on shine.com

Source description

About the role

View original

As a Microsoft Sentinel Engineer / SOC Analyst (L2/L3) in our team, your role will involve hands-on experience in end-to-end Sentinel implementation and SOC operations. You will be responsible for onboarding data sources, building detections, automating response, and handling security incidents. Key Responsibilities: - Deploy and configure Microsoft Sentinel in Azure environment - Connect and onboard data sources such as Azure AD, Office 365, Defender, Firewalls, Servers, AWS/GCP logs - Build and optimize Analytics Rules (Scheduled & NRT) and KQL-based detection queries - Develop Workbooks and Dashboards - Configure Data Connectors & Log ingestion pipelines - Implement UEBA & threat intelligence integration - Develop cost optimization & log retention strategy - Monitor and investigate incidents in Sentinel - Perform threat hunting using KQL - Conduct incident triage, analysis, and response - Work on Phishing, Malware, Insider threats, and Suspicious logins - Tune alerts to reduce false positives - Perform root cause analysis (RCA) and collaborate with IR teams for escalation - Develop Playbooks using Logic Apps for automation - Automate incident response workflows - Integrate Sentinel with SOAR tools and ITSM tools (ServiceNow) Required Skills: - Strong experience in Microsoft Sentinel (Implementation + Ops) - Proficiency with KQL (Kusto Query Language) - Familiarity with Azure services like Log Analytics, Azure AD, Defender - SOC experience (L2/L3 preferred) - Expertise in threat detection & incident response - Knowledge of MITRE ATT&CK framework Join us in leveraging your skills to enhance our security operations and contribute to a dynamic and challenging work environment. As a Microsoft Sentinel Engineer / SOC Analyst (L2/L3) in our team, your role will involve hands-on experience in end-to-end Sentinel implementation and SOC operations. You will be responsible for onboarding data sources, building detections, automating response, and handling security incidents. Key Responsibilities: - Deploy and configure Microsoft Sentinel in Azure environment - Connect and onboard data sources such as Azure AD, Office 365, Defender, Firewalls, Servers, AWS/GCP logs - Build and optimize Analytics Rules (Scheduled & NRT) and KQL-based detection queries - Develop Workbooks and Dashboards - Configure Data Connectors & Log ingestion pipelines - Implement UEBA & threat intelligence integration - Develop cost optimization & log retention strategy - Monitor and investigate incidents in Sentinel - Perform threat hunting using KQL - Conduct incident triage, analysis, and response - Work on Phishing, Malware, Insider threats, and Suspicious logins - Tune alerts to reduce false positives - Perform root cause analysis (RCA) and collaborate with IR teams for escalation - Develop Playbooks using Logic Apps for automation - Automate incident response workflows - Integrate Sentinel with SOAR tools and ITSM tools (ServiceNow) Required Skills: - Strong experience in Microsoft Sentinel (Implementation + Ops) - Proficiency with KQL (Kusto Query Language) - Familiarity with Azure services like Log Analytics, Azure AD, Defender - SOC experience (L2/L3 preferred) - Expertise in threat detection & incident response - Knowledge of MITRE ATT&CK framework Join us in leveraging your skills to enhance our security operations and contribute to a dynamic and challenging work environment.

One address, no account. We’ll tell you when matching roles go live.

More at Norwin Technologies

Related open roles

View all roles