02 Oct
|
Lorven Technologies
|
Bangalore Metropolitan Area
02 Oct
Lorven Technologies
Bangalore Metropolitan Area
- Design, develop, and maintain automation workflows using Azure Logic Apps, including reusable workflow templates and modules.
- Build and manage SOC automation playbooks in Microsoft Sentinel, triggered via automation rules for alert/incident/entity-driven response.
- Automate incident response activities such as enrichment, containment, and notifications, improving SOC efficiency and consistency.
- Develop and maintain automation scripts using PowerShell or Python to support SOC workflows and response actions.
- Integrate workflows with Microsoft security platforms including Microsoft Sentinel, Defender, and Entra ID.
- Build API-based integrations using REST APIs and Microsoft Graph API for identity/session response and enrichment.
- Implement automated response actions such as account disablement, session revocation, IP blocking, and endpoint isolation (with appropriate guardrails/approvals).
- Integrate Sentinel automation with ITSM tools (e.g., ServiceNow) for incident/ticket creation and updates.
- Use Azure Key Vault for secure secrets/credential handling and ensure least-privilege access patterns.
- Monitor Logic App executions, troubleshoot workflow failures, and improve reliability, performance, and execution cost. (Internal KT notes also emphasize retention/cost awareness and continuous optimization.)
- Maintain logging, auditing, and compliance visibility for all automated actions and integrations.
- Collaborate with SOC analysts and platform teams to identify and deliver automation opportunities; produce technical documentation, runbooks, and workflow diagrams.
📌 Azure Logic Apps (Bangalore Metropolitan Area)
🏢 Lorven Technologies
📍 Bangalore Metropolitan Area