19 Aug
|
TERRALOGIC
|
Bengaluru
19 Aug
TERRALOGIC
Bengaluru
Job Title: Lead Microsoft Security Engineer (XDR/AI/SOAR)
YOE Required: 7+ years
Location: Bangalore
Work Mode: 5 days work from office
Core Technologies: Microsoft Sentinel, Microsoft Defender XDR, KQL, Azure Logic Apps, SOAR
Role Summary
We are looking for a visionary Lead Security Engineer to architect, manage, and evolve our security posture within the Microsoft 100% cloud-native stack. As the technical lead, you will bridge the gap between reactive threat hunting and proactive AI-driven defence. You aren't just watching the "blinkenlights" you are building the automated engines that respond to threats before they become headlines.
Key Responsibilities
1. SIEM & Detection Engineering (Microsoft Sentinel)
● Architect & Optimize: Design and maintain the Sentinel workspace, ensuring cost efficient log ingestion and optimized data retention.
● KQL Mastery: Write, tune, and maintain complex Kusto Query Language (KQL)
queries for advanced hunting and detection rules.
● Threat Hunting: Lead proactive hunting exercises using Sentinel Workbooks and
Notebooks to identify stealthy adversaries.
2. Unified XDR Management (Microsoft Defender)
● Full Stack Integration: Oversee the end to end configuration of the Defender suite
(Defender for Endpoint, Identity, Office 365, and Cloud Apps).
● Incident Response: Act as the Tier 3 escalation point for high-severity incidents,
leading the investigation from initial alert to remediation.
● Posture Management: Utilize Defender for Cloud to drive secure scores and enforce compliance guardrails across multi cloud environments.
3.
AI-Driven Defense (Copilot for Security)
● Prompt Engineering: Design and refine custom "Promptbooks" and security specific agents to accelerate incident summarization and triage.
● AI Integration: Leverage Copilot to reverse engineer malicious scripts and translate complex telemetry into natural language for executive stakeholders.
● Capacity Planning: Stay ahead of the curve by implementing the latest Copilot plugins and integrating them into standard SOC workflows.
4. Automation & SOAR (Azure Logic Apps)
● Workflow Automation: Build and maintain sophisticated Logic App playbooks to automate repetitive tasks (e.g., auto isolating compromised devices, disabling at risk accounts).
● API Integration: Connect Sentinel and Defender to external ITSM tools (like
ServiceNow) and third party APIs to create a unified response ecosystem.
Technical Qualifications
● Experience: 7+ years in Cybersecurity, with at least 3 years specifically leading teams in a Microsoft centric environment.
● Tooling: Expert level proficiency in Microsoft Sentinel, Microsoft Defender XDR, and
Azure Logic Apps.
● AI/ML: Hands-on experience with Microsoft Copilot for Security (or early adopter proficiency in Generative AI for SecOps).
● Coding: Robust proficiency in KQL and PowerShell; experience with Python or REST
APIs is a significant plus.
Preferred Certifications
● SC-100: Microsoft Cybersecurity Architect
● SC-200: Microsoft Security Operations Analyst
● AZ-500: Microsoft Azure Security Engineer Associate
📌 Microsoft Security Architect (Bengaluru)
🏢 TERRALOGIC
📍 Bengaluru