Senior Azure Monitoring and Logging Engineer

Vsync Solutions — Canada · Posted ~4 hours ago

Senior Full-time

Skills

Azure monitoring Azure logging Log Analytics Azure Monitor Agent Data Collection Rules Azure Policy Diagnostic settings Entra ID SIEM integration Splunk Log governance Cloud security Microsoft Azure Azure Monitor SIEM

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A Senior Azure Monitoring and Logging Engineer will design and govern an enterprise-wide logging architecture across multiple cloud subscriptions and application environments. Responsibilities include auditing logging coverage, centralizing platform and identity telemetry, deploying monitoring agents and data collection rules, enforcing diagnostic settings through policy automation, optimizing retention costs, and integrating telemetry with SIEM platforms.

Highlights

Senior cloud engineering role focused on enterprise-scale observability, centralized logging, security governance, cost optimization, compliance automation, and SIEM integration across Azure environments.

Description

The Senior Azure Monitoring and Logging Engineer will design, centralize, and enforce a governed enterprise Azure logging architecture across all subscriptions and application environments. This role ensures secure log ingestion, cost-optimized retention, compliance enforcement via policy, and seamless integration with SIEM/Splunk platforms. Key Deliverables & Responsibilities: · Logging Gap Audit: Conduct a comprehensive logging audit across cross-subscription Azure infrastructure, tenant activities, and workload logs. · Centralized Log Architecture: Centralize Azure Activity logs, Entra ID logs, and resource-level telemetry into structured Log Analytics Workspaces. · Agent & DCR Deployment: Deploy Azure Monitor Agent (AMA) and configure Data Collection Rules (DCR) for targeted, efficient telemetry gathering. · Automated Governance: Draft and enforce Azure Policy with DeployIfNotExists (DINE) remediation to guarantee auto-enablement of diagnostic settings across new/existing resources. · Security & Archival Controls: Configure retention tiers, Azure Private Link, Managed Identities, fine-grained RBAC, and secure log streaming to Splunk/SIEM. · Alerting & Sign-Off: Develop actionable KQL-based alert rules, validate operational security controls, and deliver comprehensive operational runbooks. Required Core Skills & Technical Expertise · Azure Monitoring Suite: Expertise in Azure Monitor, Log Analytics Workspaces, Azure Monitor Agent (AMA), Diagnostic Settings, and Data Collection Rules (DCR). · Kusto Query Language (KQL): Advanced KQL authoring for complex log querying, dashboarding, and alerting rules. · Azure Policy & Governance: Deep working knowledge of Azure Policy, initiative definitions, and DeployIfNotExists (DINE) automated remediation. · Security & Connectivity: Proficiency with Entra ID, Azure RBAC, Managed Identities, Azure Private Link, and secure SIEM/Splunk integration. · Automation & Cost Control: Hands-on scripting using PowerShell, Azure CLI, Terraform, Bicep, or Python, with focus on log retention cost optimization. Preferred Candidate Profile & Qualifications · Experience: 5+ years in Azure cloud engineering with recent delivery of centralized enterprise logging frameworks. · Certifications: Microsoft Certified: Azure Solutions Architect, Azure Security Engineer, or DevOps Engineer Expert. · Domain Expertise: Regulated industry experience (banking/finance preferred) with strict data residency and audit standards. · Screening Criteria: Candidates will be screened specifically for multi-subscription policy enforcement, cross-workspace security, KQL proficiency, and storage cost controls.