FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Microsoft Sentinel and security platform engineering, with a strong focus on detection engineering, automation, and security architecture. Proficient in developing high-fidelity detections, threat-hunting queries, and integrating security controls across various environments.
Highest-signal resume keywords
Microsoft Sentinel AdministrationDetection EngineeringSecurity ArchitectureAutomation with PowerShell and PythonSIEM Integration
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Detection EngineeringSecurity Monitoring ArchitectureHigh-Fidelity DetectionsThreat-Hunting QueriesData Collection RulesVulnerability RemediationTechnical Risk AssessmentKQLMITRE ATT&CK MappingCross-Data Correlation
Tools & Technologies
Microsoft Defender XDRLogic AppsAzure FunctionsREST APIsAzure Monitor AgentLog AnalyticsWindows Event ForwardingSysmonAzure DevOpsCribl
Certifications & Qualifications
Microsoft SC-200Microsoft AZ-500
Industry Keywords
Security EngineeringCloud SecurityInfrastructure SecurityTelemetryDetection-as-Code
Tech Stack
Tools & technologiesAzureCloudCyber SecurityPython
About the role
Key responsibilities & impact- Act as a Subject Matter Expert for Microsoft Sentinel, detection engineering, security monitoring architecture, and associated security platforms
- Design, develop, test, deploy, and tune analytics rules, correlation logic, threat-hunting queries, and reusable detection content aligned with MITRE ATT&CK
- Engineer and optimise data connectors, ingestion pipelines, Data Collection Rules, custom parsers, custom tables, and API-based integrations
- Develop logging standards, onboarding patterns, use-case documentation, and governance for the detection engineering lifecycle
- Design and implement automation using Logic Apps, Azure Functions, REST APIs, PowerShell, and Python
- Perform security engineering activities including secure solution design, technical risk assessment, platform hardening, vulnerability remediation, and security control validation
- Support integration and engineering of endpoint, identity, cloud, network, and infrastructure security controls with the SIEM and Defender ecosystem
- Build Sentinel Workbooks, dashboards, platform health monitoring, and KPI/KRI reporting for the Proactive Security function
- Produce and maintain High-Level Designs, Low-Level Designs, engineering standards, operating procedures, and support documentation
- Lead platform enhancements, proof-of-concepts, migrations, upgrades, troubleshooting, and technical support during critical incidents and major changes
- Collaborate with Security Operations, Infrastructure, Cloud, and Application teams to deliver scalable telemetry, high-fidelity detections, secure integrations, and continuous improvement of proactive security monitoring
Requirements
What you’ll need- Proven experience in SIEM, detection, or security platform engineering within a large enterprise environment
- Strong hands-on experience with Microsoft Sentinel and Microsoft Defender XDR, including Endpoint, Identity, and Cloud
- Experience developing and tuning high-fidelity detections, threat-hunting queries, cross-data correlation, and contextual enrichment
- Experience onboarding infrastructure, cloud, application, and security telemetry into a SIEM
- Practical experience with security architecture, platform hardening, vulnerability remediation, technical risk assessment, and security control validation
- Experience with REST APIs, PowerShell, Python, automation, enterprise troubleshooting, and operational support
- Experience applying Detection-as-Code, CI/CD, source control, and peer-review practices
- Advanced Microsoft Sentinel administration, architecture, KQL, analytics rules, hunting, workbooks, watchlists, playbooks, and optimisation
- Knowledge of Azure Monitor Agent, Azure Arc, Data Collection Rules, Log Analytics, custom tables, parsers, and custom ingestion
- Knowledge of Windows Event Forwarding and Collection, XPath filtering, Windows Event IDs, Sysmon, and PowerShell logging
- Knowledge of Azure Functions, Logic Apps, REST APIs, PowerShell, Python, and security workflow automation
- Knowledge of MITRE ATT&CK mapping, threat-informed defence, detection coverage analysis, and use-case lifecycle management
- Security engineering knowledge across endpoint, identity, cloud, network, and hybrid infrastructure controls
- Knowledge of Azure DevOps or equivalent Git-based CI/CD, Infrastructure-as-Code concepts, secure development practices, and tools such as Cribl
- Degree or equivalent professional experience in Information Technology, Cyber Security, Engineering, or a related discipline
- Willingness to provide planned out-of-hours support for critical upgrades and major changes when required
- Microsoft SC-200 or AZ-500 certifications are desirable
- Additional cloud, SIEM, security engineering, or automation certifications are advantageous
Benefits
Comp & perks- Competitive compensation
- Career growth opportunities
- Access to continuous learning and certifications
- Work with cutting-edge Azure technologies
- Opportunity to work on impactful cloud initiatives across various industries
- Access to cutting-edge MXDR platform and proprietary SecOps tools
- Rapid growth and fast-track leadership opportunities
- Culture of open feedback and innovation
