Delivery Engineer – Microsoft Sentinel Security Engineer
Noventiq GCC · Mascate
وصف الوظيفة
About the role
We are seeking a hands‑on Delivery Engineer with deep expertise in Microsoft Sentinel to design, implement and operate our security monitoring and response platform across Azure and Microsoft 365 environments. The role combines SIEM engineering, SOAR automation, detection development, threat hunting and incident response to protect the organization’s assets.
Key responsibilities
- Design, deploy and administer Microsoft Sentinel, including data connectors, Log Analytics workspaces and Data Collection Rules.
- Develop and optimise analytics rules, hunting queries, workbooks, dashboards and reports using Kusto Query Language (KQL).
- Create and maintain SOAR playbooks with Azure Logic Apps and Automation Rules.
- Integrate Sentinel with Microsoft security services (Defender XDR suite) and Azure resources.
- Perform threat hunting, incident investigation and response using Sentinel.
- Build detection use cases aligned with the MITRE ATT&CK framework and reduce false positives.
- Monitor SIEM health, log ingestion, platform performance and manage cost optimisation.
- Prepare technical documentation, runbooks and operational reports.
- Integrate security events from enterprise products such as Palo Alto, Fortinet, Cisco, Check Point, CrowdStrike, Zscaler, Proofpoint, F5 BIG‑IP and cloud platforms (AWS, GCP).
- Configure ASIM normalization, Content Hub solutions, custom parsers, Syslog, CEF, Windows Events, REST API connectors and AMA Agent.
- Develop advanced KQL for analytics, UEBA investigations, watchlists and workbooks.
- Manage Sentinel and Azure RBAC, least‑privilege access and watchlist utilisation.
Required profile
- 3–8 years of experience in Security Operations or Security Engineering.
- Minimum 2 years of hands‑on Microsoft Sentinel implementation and administration.
- Strong knowledge of Microsoft Sentinel architecture, deployment and optimisation.
- Excellent proficiency in Kusto Query Language (KQL).
- Proven experience integrating a wide range of security products with Sentinel.
Required skills
- Microsoft Sentinel
- Azure Logic Apps
- Azure Automation Rules
- Kusto Query Language (KQL)
- Azure Functions
- Azure RBAC / Azure AD
- Microsoft 365 security services
- Microsoft Defender XDR (Endpoint, Identity, Office 365, Cloud Apps, Cloud)
- ASIM normalization, Content Hub, custom parsers
- Syslog, CEF, Windows Event logs, REST API connectors, AMA Agent
- MITRE ATT&CK framework
- Threat intelligence feed integration
- Watchlists and UEBA
- Palo Alto Networks firewalls
- Fortinet FortiGate
- Cisco Secure Firewall/ISE
- Check Point Security Gateway
- CrowdStrike Falcon
- Zscaler ZIA/ZPA
- Proofpoint Email Protection
- F5 BIG‑IP
- AWS and GCP log integration
Questions fréquentes
لماذا تبلغ عن هذا العرض؟
اكتشف المزيد
الرواتب والأدلة وعمليات البحث في Oman.
قدم طلبك في 30 ثانية
أدخل بريدك الإلكتروني للتقديم. سيتم إنشاء حساب تلقائياً.
بالمتابعة، أنت توافق على شروط الاستخدام.
لديك حساب بالفعل؟ تسجيل الدخول
عزز فرصك
حمّل سيرتك الذاتية وسنقترح عليك الوظائف التي تناسب ملفك.
جاري تحليل سيرتك الذاتية...
Noventiq GCC
Mascate