ROLE DESCRIPTION:
We are seeking an experienced Microsoft Sentinel Engineer to join the Cyber Defense Center (CDC) and support the development,
optimization, and operation of our Microsoft Sentinel platform.
The successful candidate will be responsible for designing and implementing security monitoring capabilities, onboarding and
managing security telemetry, developing detection use cases, and driving security automation initiatives. The role requires strong
technical expertise in Microsoft Sentinel, Kusto Query Language (KQL), log management, and security orchestration, as well as the
ability to collaborate effectively across security and IT teams.
KEY RESPONSIBILITIES:
Design, implement, and maintain Microsoft Sentinel security monitoring capabilities. Onboard, normalize, and optimize security log sources from cloud and on-premises platforms. Develop and maintain analytics rules, detection logic, watchlists, workbooks, and hunting queries. Design and implement security automation and orchestration workflows using Logic Apps and Sentinel playbooks. Perform log source onboarding, data quality validation, and telemetry coverage assessments. Develop and optimize KQL queries for threat detection, investigation, reporting, and threat hunting. Collaborate with Security Operations analysts to improve detection coverage and reduce false positives. Support threat hunting and incident investigation activities through telemetry analysis and content development. Contribute to the continuous improvement of CDC monitoring, detection, and response capabilities. Maintain technical documentation, engineering standards, and operational procedures related to Microsoft Sentinel. REQUIRED EDUCATION AND EXPERIENCE:
- Minimum 5 years of experience in cybersecurity, with a strong focus on security operations, detection engineering, or SIEM
engineering.
Strong experience onboarding and managing log sources within SIEM platforms. Strong experience developing security detections and analytics content. Experience designing and implementing security automation workflows. Experience working with Microsoft security technologies and Microsoft Defender XDR are considered an advantage. Relevant Microsoft certifications are highly desirable (e.g., SC-200, AZ-500). REQUIRED SKILLS:
Fluent English speaking and writing Ability to collaborate cross-functionally with IT experts throughout the organization. Positive mindset, curiosity, open-mindedness, and a proactive approach to problem-solving. Excellent team player with strong interpersonal skills and a collaborative mindset. > Starting Date: 1st of September
>
> End Date: Indefinite term (30-day notice period)
>
> Working Hours: 40 hours/week
>
> Location: Europe