04 Sep
|
MindBrain
|
India
– Microsoft Security Operations / Microsoft Sentinel Engineer
Experience: 8+ Years
Shift: 2:00 PM – 11:00 PM
Employment Type: Contract
Location: Remote
Job Overview
We are seeking an experienced Microsoft Security Operations / Microsoft Sentinel Engineer to design, build, and operationalize a 24/7 Managed Security Operations (SOC/MXDR) service for Microsoft 365-centric environments.
The ideal candidate will have strong hands-on expertise in Microsoft Sentinel, Microsoft Defender, detection engineering, incident response, and managed SOC operations. This is a senior engineering role requiring the ability to establish and mature security operations capabilities and successfully transition them to managed services teams.
Key Responsibilities
- Conduct discovery and gap-analysis workshops with clients and key stakeholders.
- Assess customer environments, infrastructure/node counts, and required security log sources.
- Design and implement Microsoft Sentinel environments end-to-end.
- Configure and manage:
- Data Connectors
- Data Collection Rules (DCRs)
- Analytics Rules
- Watchlists
- UEBA
- Workbooks
- Develop and maintain Logic App playbooks for security automation and incident response.
- Optimize Microsoft Sentinel log ingestion and operational costs.
- Deploy, configure, tune, and manage Microsoft Defender for Endpoint at scale.
- Configure and optimize:
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Develop and enhance detection use cases mapped to the MITRE ATT&CK; framework.
- Create and maintain incident triage, escalation, containment, and response runbooks.
- Establish and operationalize 24/7 SOC processes, including:
- L1/L2 operational procedures
- Shift handovers
- SLAs
- Escalation paths
- DFIR handoffs
- Produce audit-ready monitoring, detection, and security evidence for compliance requirements.
- Deliver multi-tenant and white-labelled security services using Microsoft Lighthouse.
- Evaluate and integrate third-party MDR/security platforms such as SentinelOne, where required.
- Train managed services teams and provide structured knowledge transfer and operational documentation.
- Support presales activities, including discovery calls, solution scoping, effort estimation, cost estimation, and technical tender responses.
- Document security architectures, operational processes, and technical solutions.
Mandatory Skills & Experience
- 8+ years of relevant experience in Cybersecurity, Security Operations, SOC, or Managed Security Services.
- Strong hands-on experience building at least one greenfield Microsoft Sentinel environment end-to-end.
- Strong proficiency in KQL (Kusto Query Language).
- Extensive experience with Microsoft Sentinel SIEM and SOAR capabilities.
- Hands-on experience deploying, configuring, and tuning Microsoft Defender for Endpoint at scale.
- Strong practical experience in Incident Response, including triage, investigation, containment,
remediation, and DFIR handoff.
- Experience in detection engineering and developing security use cases aligned with the MITRE ATT&CK; framework.
- Experience delivering multi-tenant or white-label security services within an MSSP or managed services workplace.
- Mandatory Microsoft SC-200 certification.
- Strong client-facing skills with the ability to independently conduct discovery and security assessment workshops.
- Proven experience creating technical documentation, SOC runbooks, and training operational teams.
Good to Have
- Experience producing security and compliance evidence packs for:
- Cyber Essentials
- DCC
- NIST CSF
- ISO 27001
- Azure Security experience covering:
- Azure Landing Zones
- Azure Policy
- Microsoft Entra ID
- Azure Key Vault
- Automation experience using:
- Azure Logic Apps
- PowerShell
- Bicep
- Terraform
- Exposure to AWS Security services such as:
- Amazon GuardDuty
- AWS Security Hub
- Experience with third-party MDR, XDR, or endpoint security platforms such as SentinelOne.
Personal Skills
- Excellent communication and stakeholder-management skills.
- Strong analytical and problem-solving abilities.
- Self-driven and confident in working independently as well as collaboratively within a team.
- Ability to work effectively across different cultures, organizational boundaries, and time zones.
- Strong delivery orientation with the ability to manage multiple priorities and work under strict deadlines.
- Ability to lead technical discussions and communicate complex security concepts to technical and non-technical stakeholders.
📌 Microsoft Security Operations (SOC) Engineer (8+ yrs)
🏢 MindBrain
📍 India