17 Sep
|
Xencia Technology Solutions
|
Bengaluru
17 Sep
Xencia Technology Solutions
Bengaluru
L2 Security Engineer (Implementation Microsoft Sentinel & Defender Suite)
Role: L2 Security Implementation Engineer
Experience: Minimum 5 Years of Experience
Specialization: Microsoft Sentinel, Microsoft Defender XDR Suite
Job Type: Full-Time, 9AM - 7PM from Office in Bangalore (Implementation / Delivery)
Job Summary
We are looking for a skilled L2 Implementation Engineer with 4–5 years of hands-on experience deploying and configuring Microsoft Sentinel and Microsoft Defender products. This role focuses entirely on implementation, onboarding, integrations, policy configuration, customer deployments, and technical project delivery—not SOC monitoring.
Key Responsibilities (Implementation-Focused)
Microsoft Sentinel – Implementation
•
Deploy and configure Log Analytics Workspace, data retention, workspace architecture.
•
Onboard data sources using connectors (Azure services, M365, Defender, Syslog, CEF agents, firewalls, proxies, SaaS apps).
•
Configure Log Analytics Agents / AMA on Windows, Linux, and network appliances.
•
Implement workbooks, dashboards, and basic analytic rules as part of initial setup.
•
Configure and test automation rules & SOAR Playbooks (Logic Apps) to meet customer use cases.
•
Integrate Sentinel with
o
Microsoft Defender XDR o
Azure AD / Entra ID logs o
Azure Activity Logs o
On-prem servers o
Firewalls (Palo Alto, Fortinet, Checkpoint)
Microsoft Defender Suite – Deployment & Configuration
Defender for Endpoint (MDE)
•
Onboard Windows, macOS, Linux devices using onboarding scripts, Intune, Group Policy.
•
Configure AV, EDR, ASR rules, firewall, network protection, web filtering, and device control.
•
Build and deploy endpoint security baselines using Intune or GPO.
Defender for Identity (MDI)
•
Deploy sensors on Domain Controllers.
•
Configure directory services integration.
•
Validate lateral movement and identity monitoring.
Defender for Cloud Apps (MDA/M365D Apps)
•
Configure app connectors (O365, AWS, GCP, Salesforce, ServiceNow).
•
Deploy session control, app discovery, conditional access app control.
•
Enable policies for DLP, file governance, and compliance.
Defender for Office 365
•
Configure Safe Links, Safe Attachments, anti-phishing policies, impersonation protection.
•
Integrate O365 signals with Sentinel.
Defender for Cloud (Azure Security Center)
•
Configure subscriptions, security policies, recommendations & workload protections.
•
Enable defender plans for VMs, storage, SQL, containers, key vault, etc.
Additional Responsibilities
•
Gather customer requirements and convert them into technical implementation steps.
•
Prepare HLD/LLD documentation, architecture diagrams, implementation plans.
•
Perform POCs, pilots, environment assessments, and configuration validation.
•
Troubleshoot onboarding issues, connector failures, integration errors.
•
Conduct knowledge transfer (KT) sessions to customers post-deployment.
•
Work with Microsoft Intune for onboarding Defender & deploying policies (if required).
•
Good Power shell and Linux scripting skills
•
Have experience to handle and execute the end to end implementation of sentinel individually
Required Skills
•
Strong experience implementing
o
Microsoft Sentinel o
Defender for Endpoint o
Defender for Identity o
Defender for Office 365
o
Defender for Cloud Apps o
Defender for Cloud (Azure)
•
Valuable hands-on knowledge of:
o
Azure Log Analytics o
KQL (basic-intermediate for validation)
o
Azure Logic Apps (SOAR playbooks)
o
Azure AD / Entra ID logs
•
Strong understanding of onboarding methods, connectors, log ingestion, and device integrations.
📌 Cyber Security Engineer (Bengaluru)
🏢 Xencia Technology Solutions
📍 Bengaluru