Description
Role Summary:
We are looking for a technically strong and process-driven SIEM Integration & Engineering Specialist with proven experience in Microsoft Sentinel to lead and execute end-to-end integration, onboarding, log parsing, transformation, and ingestion optimization activities. You will own the engineering lifecycle of log source integration, tuning, troubleshooting ingestion issues, and developing reusable automation/SOPs to support multiple enterprise and MSSP customers.
Key Responsibilities: Integration & Configuration
Create and maintain onboarding checklists for all current log sources: log size estimation, ingestion strategy, placement logic (Syslog/CommonSecurityLog/CustomLog), best onboarding method (agent, API, etc.).
Evaluate and implement native vs custom ingestion using REST APIs, syslog, CEF, Syslog-NG, and event hubs.
Manage Data Collection Rules (DCRs) for structured and unstructured data including transformations, filters, multi-line handling, and custom table mapping.
Author SOPs and “How-to” documentation for custom log normalization,
transformation logic, and DCR limitations.
Recommend and justify table selection strategy (e.g., CommonSecurityLog vs. CustomLog) based on customer needs and Sentinel performance.
Ingestion Optimization & Tuning
Identify and resolve log duplication issues using correlation, diagnostic settings, and parsing analysis.
Choose between agent-based and agentless ingestion strategies; document troubleshooting methods and share reusable configurations.
Design ingestion pipelines considering performance throttling, throughput optimization, and pre-ingestion routing (like log routers, collectors, proxies).
Collaborate with customers to align ingestion design with retention policies and data costs.
Health Monitoring & Troubleshooting
Develop and maintain log rotation configurations/scripts for Linux and Windows sources, including detection and remediation of rotation issues.
Create scheduled health ch
📌 Associate - Cybersecurity (Pune)
🏢 Inspira
📍 Pune