Mô Tả Công Việc
About the Role:We are looking for a highly skilled Senior Engineer to lead and elevate our SIEM & Security Automation capabilities across the Group. In this role, you will be the technical owner of our Microsoft Sentinel platform—designing, engineering, and optimizing advanced detection use cases and automated response workflows that strengthen our cyber defence posture. Requirements:As an SIEM & Security Automation (Microsoft Sentinel), you will be responsible for the following tasks:Lead the administration, configuration, and optimization of the Group’s SIEM/SOAR platforms, with a primary focus on Microsoft Sentinel.Design, build, and maintain advanced analytics rules, UEBA use cases, hunting queries (KQL), workbooks, playbooks, and automations within Sentinel.Develop, customize, and maintain Logic Apps, Azure Functions, and other automation workflows to enhance detection, response, and remediation capabilities.Drive the continuous improvement of detection engineering practices, ensuring high-fidelity alerts and reduced false positives.Oversee the end-to-end lifecycle of security incident response automation, including design, testing, deployment, and documentation.Collaborate closely with Security Operations, Cloud, Infrastructure, and Application teams to ensure seamless integration of data sources and automation workflows.Evaluate new Sentinel features, Azure security capabilities, and emerging SOAR technologies to recommend enhancements aligned with Group Information Security strategies.Lead or support SIEM/SOAR transformation initiatives across Business Units to ensure consistent deployment, standards, and operational excellence.Establish and maintain coding standards, reusable components, and development best practices for security automation.Provide guidance, mentorship, and technical oversight to junior engineers and project teams.
Xem toàn bộ Mô Tả Công Việc
Yêu Cầu Công Việc
Minimum 4–8 years of experience in Security Operations, SIEM Engineering, SOAR Engineering, or Cloud Security Engineering roles.Strong hands-on experience with Microsoft Sentinel, including KQL query development, analytics rule tuning, data connector integration, and custom workbook creation.Proficient in Logic Apps development, including API connections, custom connectors, modular design, and workflow orchestration.Solid programming experience in languages such as:PowerShellPythonor other scripting languages used for automation and Azure integrations.Deep understanding of SIEM architecture, log ingestion pipelines, parsing/normalization, and security telemetry design.Strong knowledge of Azure cloud services, including Azure Monitor, Azure Functions, Event Hub, Log Analytics, Azure AD/Entra ID, and security-related services.Demonstrated experience developing security automation playbooks and orchestrating incident response workflows.Excellent analytical, problem-solving, and stakeholder communication skills.Proven ability to lead complex detection engineering or SOAR automation projects.Certifications such as Microsoft Cybersecurity Architect (SC-100), Azure Security Engineer (AZ-500), Microsoft Sentinel (SC-200), or CISSP are highly advantageous.
Xem toàn bộ Yêu Cầu Công Việc
Hình thức
Full-time
Quyền Lợi
Attractive salary and benefits Hybrid working modeFull salary in probation & 13th month salarySocial insurance on full salary from probationExtensive leave up to 18 days per yearAnnual health check
Mức lương
Thỏa thuận
Báo cáo tin tuyển dụng: Nếu bạn thấy rằng tin tuyển dụng này không đúng hoặc có dấu hiệu lừa đảo,
hãy phản ánh với chúng tôi.
Tham khảo: 10 Dấu hiệu nhận biết hành vi lừa đảo qua tin tuyển dụng.
Tham khảo: 10 Dấu hiệu nhận biết hành vi lừa đảo qua tin tuyển dụng.