– Microsoft Sentinel Architect
Job Title: Microsoft Sentinel Architect
Location: India
Experience: 10+ Years
About the Role
We are seeking an experienced Microsoft Sentinel Architect to design, implement, and manage enterprise-scale cloud security monitoring solutions. The ideal candidate will have extensive experience in Microsoft Sentinel, Splunk Administration, SIEM Operations, Security Architecture, and Automation to support global security operations and strengthen cybersecurity posture.
Key Responsibilities
Microsoft Sentinel Architecture & Engineering
- Design and develop security architectures leveraging Microsoft Sentinel to meet business and compliance requirements.
- Implement, configure, and optimize Microsoft Sentinel for security monitoring and threat detection.
- Develop and maintain analytics rules, workbooks, playbooks, and automation workflows.
- Integrate multiple log sources and security tools into Microsoft Sentinel.
- Create security use cases and detection strategies to improve SOC effectiveness.
- Support incident investigation, threat hunting, and response activities.
Splunk Administration & Engineering
- Administer and maintain Splunk infrastructure including Search Heads, Indexers, and Universal Forwarders.
- Troubleshoot Splunk server, deployment, and forwarder-related issues.
- Manage data onboarding, index administration, and retention policies.
- Build and maintain dashboards, reports, alerts, and knowledge objects.
- Support users in designing production-quality dashboards and reports.
- Monitor platform performance, capacity planning, and optimization.
- Implement automation scripts for maintenance and alerting tasks.
- Support Splunk deployments across Linux, Unix, and Windows environments.
- Work with Cribl for data routing, filtering, and optimization.
Required Skills
- 10+ years of experience in Cybersecurity, SIEM, and Security Operations.
- Strong hands-on experience with Microsoft Sentinel Architecture and Engineering.
- Extensive experience administering and supporting Splunk Enterprise environments.
- Experience with Azure Security Services and Microsoft Security Stack.
- Strong understanding of SIEM, SOAR, Incident Response, and Threat Hunting concepts.
- Experience integrating diverse log sources and security technologies.
- Demonstrated knowledge of ITIL principles and service management processes.
- Experience in scripting and automation using PowerShell, Python, or similar technologies.
- Robust troubleshooting and problem-solving skills.
- Excellent communication and stakeholder management skills.
Preferred Skills
- Experience with Cribl administration and optimization.
- Azure Security certifications.
- Microsoft Sentinel Certifications (SC-200, AZ-500, etc.).
- Splunk Enterprise Certified Administrator/Architect.
- Knowledge of cloud security, Zero Trust, and Security Operations Center (SOC) environments.
- Experience working in large enterprise and global support environments.
📌 Microsoft Sentinel Architect (Noida)
🏢 HCLTech
📍 Noida