Delivery Engineer – Microsoft Sentinel Security Engineer
Noventiq GCC · Mascate
Job description
About the role
We are seeking a hands‑on Delivery Engineer with deep expertise in Microsoft Sentinel to design, implement and operate our security monitoring and response platform across Azure and Microsoft 365 environments. The role combines SIEM engineering, SOAR automation, detection development, threat hunting and incident response to protect the organization’s assets.
Key responsibilities
- Design, deploy and administer Microsoft Sentinel, including data connectors, Log Analytics workspaces and Data Collection Rules.
- Develop and optimise analytics rules, hunting queries, workbooks, dashboards and reports using Kusto Query Language (KQL).
- Create and maintain SOAR playbooks with Azure Logic Apps and Automation Rules.
- Integrate Sentinel with Microsoft security services (Defender XDR suite) and Azure resources.
- Perform threat hunting, incident investigation and response using Sentinel.
- Build detection use cases aligned with the MITRE ATT&CK framework and reduce false positives.
- Monitor SIEM health, log ingestion, platform performance and manage cost optimisation.
- Prepare technical documentation, runbooks and operational reports.
- Integrate security events from enterprise products such as Palo Alto, Fortinet, Cisco, Check Point, CrowdStrike, Zscaler, Proofpoint, F5 BIG‑IP and cloud platforms (AWS, GCP).
- Configure ASIM normalization, Content Hub solutions, custom parsers, Syslog, CEF, Windows Events, REST API connectors and AMA Agent.
- Develop advanced KQL for analytics, UEBA investigations, watchlists and workbooks.
- Manage Sentinel and Azure RBAC, least‑privilege access and watchlist utilisation.
Required profile
- 3–8 years of experience in Security Operations or Security Engineering.
- Minimum 2 years of hands‑on Microsoft Sentinel implementation and administration.
- Strong knowledge of Microsoft Sentinel architecture, deployment and optimisation.
- Excellent proficiency in Kusto Query Language (KQL).
- Proven experience integrating a wide range of security products with Sentinel.
Required skills
- Microsoft Sentinel
- Azure Logic Apps
- Azure Automation Rules
- Kusto Query Language (KQL)
- Azure Functions
- Azure RBAC / Azure AD
- Microsoft 365 security services
- Microsoft Defender XDR (Endpoint, Identity, Office 365, Cloud Apps, Cloud)
- ASIM normalization, Content Hub, custom parsers
- Syslog, CEF, Windows Event logs, REST API connectors, AMA Agent
- MITRE ATT&CK framework
- Threat intelligence feed integration
- Watchlists and UEBA
- Palo Alto Networks firewalls
- Fortinet FortiGate
- Cisco Secure Firewall/ISE
- Check Point Security Gateway
- CrowdStrike Falcon
- Zscaler ZIA/ZPA
- Proofpoint Email Protection
- F5 BIG‑IP
- AWS and GCP log integration
Questions fréquentes
Why are you reporting this job?
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 1 week from now
22 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Noventiq GCC
Mascate