Overview
The Microsoft Sentinel Detection Engineer will play a crucial role in enhancing enterprise security through the implementation and management of the Microsoft Sentinel platform. This contracted position involves collaborating with various teams to improve telemetry, create high fidelity detections, and automate monitoring processes, ensuring proactive security measures are in place. The engineer will leverage their expertise in detection engineering and security monitoring architecture while working closely with Security Operations, Infrastructure, Cloud, and Application teams.
Responsibilities
- Act as the subject matter expert for Microsoft Sentinel, detection engineering, and security monitoring architecture.
- Design, test, deploy, and tune analytics rules, correlation logic, and hunting queries aligned to MITRE ATT&CK.
- Engineer data connectors, ingestion pipelines, Data Collection Rules, custom parsers, custom tables, and API integrations.
- Set logging standards, onboarding patterns, and governance across the detection engineering lifecycle.
- Build automation with Logic Apps, Azure Functions, REST APIs, PowerShell, and Python.
- Integrate endpoint, identity, cloud, network, and infrastructure controls with Sentinel and the Defender ecosystem.
- Build workbooks, dashboards, platform health monitoring, and KPI reporting.
- Produce high and low-level designs and engineering standards, leading upgrades, migrations, and proof of concepts, including planned out-of-hours support for major changes.
Requirements
- Proven experience in SIEM, detection, or security platform engineering within a large enterprise environment.
- Advanced knowledge of Microsoft Sentinel, including architecture, KQL, analytics rules, hunting, workbooks, watchlists, and playbooks.
- Strong understanding of Defender XDR across Endpoint, Identity, and Cloud.
- Experience with telemetry onboarding using Azure Monitor Agent, Azure Arc, Data Collection Rules, and Log Analytics.
- Proficient in Windows Event Forwarding, XPath filtering, Sysmon, and PowerShell logging.
- Familiarity with Detection as Code using Azure DevOps or Git-based CI/CD and Infrastructure as Code concepts.
- Experience with automation using PowerShell, Python, and REST APIs.
- SC-200 or AZ-500 certification is desirable.