We are seeking an experienced Microsoft Sentinel SIEM Administrator The ideal candidate will be responsible for managing and optimizing Microsoft Sentinel, developing detection use cases, creating advanced KQL queries, implementing UEBA capabilities, automating security processes, and supporting threat hunting and incident response activities. This role requires solid expertise in SIEM content development, security analytics, automation, and proactive threat detection.
Key Skills & Responsibilities
- Manage, configure, and optimize Microsoft Sentinel SIEM platform.
- Develop and maintain security use cases, analytics rules, detection content, and alerting mechanisms.
- Perform threat hunting, incident investigation, and root cause analysis using Microsoft Sentinel.
- Design, write, and optimize KQL (Kusto Query Language) queries for threat detection, reporting, and security analytics.
- Implement and fine-tune UEBA (User & Entity Behavior Analytics)
to identify anomalous and malicious behavior.
- Integrate and manage log sources from cloud, network, endpoint, and on-premises environments.
- Build and maintain Sentinel Workbooks, Dashboards, and Reports for monitoring and compliance requirements.
- Develop and implement automation using Logic Apps, Playbooks, PowerShell, and Python.
- Monitor SIEM performance, data ingestion, retention policies, and platform health.
- Collaborate with SOC teams for alert triage, incident response, and continuous improvement of security monitoring capabilities.
- Analyze security trends and provide actionable insights to enhance the organization's security posture.
- Support regulatory and compliance requirements through effective logging, monitoring, and reporting.
📌 Lead Assistant Manager-SIEM (Noida)
🏢 EXL
📍 Noida