15 Aug
|
Microland
|
India
Job Description
:
Skills Required:- Microsoft Sentinel Implementation – Incident management, KQL queries, detection rule tuning, automation (Logic Apps/Playbooks).
Core Responsibilities
- Operate and monitor the Microsoft XDR stack:
- Perform incident triage, threat hunting, and root cause analysis using KQL and advanced hunting queries.
- Conduct containment & remediation: account disable, token revocation, IP/domain blocking, endpoint isolation.
- Build and enhance automation playbooks, detections, and dashboards.
- Provide incident reports, RCA, and hardening recommendations aligned with MITRE ATT&CK.;
Technical Requirements
- Deep hands-on expertise in Microsoft Sentinel & Defender suite.
- KQL proficiency for hunting and incident correlation.
- Knowledge of Azure AD/Entra security, Conditional Access, Identity Protection.
- Familiarity with threat intel, SOAR automation, MITRE ATT&CK; mapping.
Language & Communication
- Excellent English communication (verbal & written) is mandatory for client interaction, escalation handling, and executive reporting.
- Microsoft Sentinel – incident management, KQL queries, detection rule tuning, automation (Logic Apps/Playbooks).
- Defender for Endpoint – advanced hunting, device isolation, forensic collection.
- Defender for Identity – AD monitoring, lateral movement, credential theft detection.
- Defender for Office 365 – phishing/email attack analysis, secure attachments/links.
- Defender for Cloud Apps (MCAS) – SaaS discovery, shadow IT, DLP.
Location
:
IND-KA-Bengaluru-Ecospace1B-ML
Created On
:
17-Apr-2026
📌 Senior SME - EndPoint (EDR) (India)
🏢 Microland
📍 India