Cyber Security Senior Consultant - Sentinel

This role focuses on architecting, designing, and implementing Microsoft Sentinel and related security solutions. Responsibilities include developing Kusto Query Language queries, supporting migrations from legacy systems, performing event analysis, and creating technical documentation. The role requires experience with SIEM, detection engineering, and scripting/automation tools.

What you'd actually do

  1. Architecting, designing, and implementing Microsoft Sentinel, Microsoft Defender for Endpoint, and extended detection and response solutions across Azure, Amazon Web Services, and Google Cloud Platform environments
  2. Developing Kusto Query Language queries, functions, analytical rules, dashboards, workbooks, and automation playbooks to support monitoring, detection engineering, threat hunting, and incident response
  3. Supporting migrations from legacy security information and event management platforms to Microsoft Sentinel, including log onboarding, parser development, custom data source integration, log forwarder deployment, and log collection optimization
  4. Performing end-to-end event analysis, incident detection, escalation management, false positive tuning, and runbook-driven response activities using documented procedures and playbooks
  5. Implementing and maintaining advanced Microsoft Sentinel capabilities, including threat intelligence integration, user and entity behavior analytics, custom dashboards, workbook development, and third-party or software-as-a-service application connectivity

Skills

Required

  • 4+ years of experience architecting, designing, and implementing Microsoft Sentinel, endpoint detection and response, or extended detection and response solutions in enterprise environments
  • 4+ years of experience with security information and event management, detection engineering, log management, or security operations in Azure, Amazon Web Services, or Google Cloud Platform environments
  • Experience developing Kusto Query Language queries and functions, analytical rules, dashboards, workbooks, and automation playbooks in Microsoft Sentinel
  • Experience migrating from legacy security information and event management platforms to Microsoft Sentinel, including parser development, custom data source integration, and log collection or forwarder deployment
  • Experience with scripting or automation tools such as PowerShell, Python, or Terraform for security operations or platform administration
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.

Nice to have

  • Bachelor's degree in Computer Science, Cyber Security, Information Security, Engineering, or Information Technology
  • Experience with threat intelligence integration, user and entity behavior analytics, or threat

What the JD emphasized

  • Microsoft Sentinel
  • security information and event management
  • detection engineering
  • threat hunting
  • incident response
  • log onboarding
  • parser development
  • custom data source integration
  • log forwarder deployment
  • log collection optimization
  • event analysis
  • escalation management
  • false positive tuning
  • runbook-driven response
  • threat intelligence integration
  • user and entity behavior analytics
  • custom dashboards
  • workbook development
  • third-party or software-as-a-service application connectivity
  • Kusto Query Language