Lumen Technologies
Website:
lumen.com
Job details:
Summary
The Microsoft Sentinel Engineer is responsible for administering and maintaining Microsoft Sentinel environments. This role supports workspace configuration, log-source onboarding, analytic rule deployment, data quality, retention, alert tuning, automation support, and dashboard/report creation. The engineer collaborates with SOC, cloud, identity, IT, and customer teams to ensure Sentinel environments are reliable, cost-aware, and operationally effective.
Key Responsibilities
- Onboard new log sources into Microsoft Sentinel using native connectors, custom connectors, Syslog, API, agents, and Azure integrations.
- Configure and maintain Log Analytics workspaces, tables, parsers, watchlists, and data retention settings.
- Develop, deploy, and maintain KQL-based analytic rules, hunting queries, and alert logic.
- Support detection tuning under guidance from senior engineers, SOC analysts, and threat hunters.
- Assist with Sentinel dashboards, playbooks, workbooks, incident views, reports, and operational metrics.
- Validate data quality, ingestion health, normalization, and connector performance.
- Support Microsoft Defender, Entra ID, M365, Azure, firewall, endpoint, and third-party log integrations.
- Assist with Logic App playbooks, automation rules, and incident enrichment workflows.
- Maintain documentation, deployment guides, data dictionaries, and operational handoff materials.
- Collaborate with SOC, IT, cloud, identity, and customer teams for onboarding and ongoing platform support.
Required Qualifications
- 6-10 years of hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or similar.
- Familiarity with KQL, regular expressions, log formats, JSON, CEF, and Syslog.
- Basic understanding of Azure services, Microsoft Defender, Microsoft Entra ID, and cloud logging concepts.
- Basic scripting skills using Python, PowerShell, Bash, or similar.
- Understanding of SOC operations, detection tuning, alert triage, and incident response workflows.
- Strong documentation and communication skills.
Preferred Certifications
- Microsoft SC-200 Security Operations Analyst
- Microsoft SC-100 Cybersecurity Architect
- Microsoft AZ-500 Azure Security Engineer
- CompTIA Security+
- Microsoft SC-300 Identity and Access Administrator
- Splunk Core Certified User or equivalent SIEM certification We are an equal opportunity employer committed to fair and ethical hiring practices. We do not charge any fees or accept any payment from candidates at any stage of the recruitment process.
SIEM, Infosec
Click on Apply to know more.