Security Engineer – Microsoft Sentinel

Noventiqgcc — Oman · Posted ~1 week ago

Skills

Microsoft Sentinel SIEM SOAR KQL threat hunting incident response detection engineering Azure Microsoft 365 Azure Logic Apps Log Analytics

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Design, deploy, and manage a modern security monitoring and response platform in cloud and productivity environments. The role covers SIEM administration, log ingestion, analytics rules, KQL queries, dashboards, SOAR playbooks, threat hunting, detection engineering, incident investigation, and automated response workflows.

Highlights

Hands-on security engineering role focused on SIEM/SOAR, detection engineering, threat hunting, and incident response across Azure and Microsoft 365, with substantial opportunities for security automation and platform design.

Description

We are looking for a hands-on Security Engineer with strong expertise in Microsoft Sentinel (SIEM/SOAR) to design, implement, and manage our security monitoring and response platform. The ideal candidate should have experience in SIEM engineering, SOAR automation, detection engineering, threat hunting, and incident response within Microsoft Azure and Microsoft 365 environments. Key Responsibilities Design, deploy, and administer Microsoft Sentinel (SIEM). Configure and manage data connectors, Log Analytics Workspaces, Data Collection Rules (DCR), and log ingestion. Develop and optimize analytics rules, hunting queries, workbooks, dashboards, and reports using Kusto Query Language (KQL). Build and maintain SOAR playbooks using Azure Logic Apps and Automation Rules. Integrate Microsoft Sentinel with Microsoft security services and Azure resources. Perform threat hunting, incident investigation, and incident response using Microsoft Sentinel. Develop and fine-tune detection use cases aligned with the MITRE ATT&CK framework. Reduce false positives and continuously improve detection coverage. Monitor SIEM health, log ingestion, and platform performance. Prepare technical documentation, runbooks, and operational reports. Hands-on experience integrating and monitoring security events from enterprise security products such as Palo Alto Networks Firewalls, Fortinet FortiGate, Cisco Secure Firewall/ISE, Check Point Security Gateway, CrowdStrike Falcon, Zscaler Internet Access (ZIA)/Private Access (ZPA), Proofpoint Email Protection, and F5 BIG-IP within Microsoft Sentinel. Experience integrating Microsoft Sentinel with Microsoft Defender XDR, including Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud. Configure ASIM normalization, Content Hub solutions, and custom parsers. Configure Syslog, CEF, Windows Events, REST API connectors, AMA Agent, and custom log ingestion. Develop advanced KQL for analytics rules, hunting queries, UEBA investigations, watchlists, and workbooks. Manage Watchlists and use them within analytics rules and threat hunting. Configure and investigate Microsoft Sentinel UEBA and behavioral analytics. Integrate Threat Intelligence feeds and develop IOC-based detection use cases. Automate incident enrichment and response using Logic Apps, Automation Rules, and Azure Functions where applicable. Manage Microsoft Sentinel RBAC, Azure RBAC, and least-privilege access. Optimize data ingestion, retention policies, and Sentinel costs while maintaining required visibility. Experience integrating logs from AWS, GCP, firewalls, VPNs, IDS/IPS, and third-party security products. Required Skills 3–8 years of experience in Security Operations or Security Engineering. Minimum 2 years of hands-on Microsoft Sentinel implementation and administration. Strong expertise in Microsoft Sentinel architecture and deployment. Excellent knowledge of Kusto Query Language (KQL). Hands-on experience developing Azure Logic Apps and Sentinel SOAR playbooks. Good understanding of Azure Monitor, Log Analytics, and Data Collection Rules (DCR). Experience with incident response, threat hunting, and detection engineering. Strong understanding of MITRE ATT&CK framework. Experience with Microsoft Entra ID and Azure security services. Knowledge of PowerShell or Python scripting is an advantage. Preferred Certifications Microsoft Certified: SC-200 – Security Operations Analyst AZ-500 – Azure Security Engineer Associate SC-100 – Cybersecurity Architect Expert Location: Muscat - EMBM, Muscat, Muscat, Oman