Role & responsibilities
- SIEM and Log Onboarding
- Design, implement, and manage log onboarding for a wide range of sources (firewalls, cloud services, EDR, etc.)
- Create advanced detection use cases in SIEM platforms (e.g., Microsoft Sentinel).
- Develop and optimize Kusto Query Language (KQL) queries for threat detection and hunting.
- SOAR Integration and Automation
- Design and deploy automated workflows to streamline triage, containment, and response using SOAR platforms (e.g., Palo Alto XSOAR, Microsoft Sentinel SOAR).
- Maintain and enhance playbooks and integrations for alert enrichment, ticketing, and incident response.
- Endpoint and Extended Detection & Response
- Configure and manage EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender XDR).
- Analyze endpoint telemetry to detect and respond to sophisticated threats.
- Cloud Security & Azure Expertise
- Implement cloud-native security controls across Microsoft Azure.
- Apply Azure security best practices including RBAC, NSGs, Key Vault, Defender for Cloud, and Azure Policies.
📌 SIEM Sentinel Engineer (Hyderabad)
🏢 PwC
📍 Hyderabad