- Company Name
- Seneca Resources
- Job Title
- Software developer
- Job Description
-
**Job Title**
Senior Software Developer – Microsoft Sentinel (SOAR & UEBA)
**Role Summary**
Lead design, development, and optimization of Microsoft Sentinel SOAR playbooks and UEBA analytics for a public‑sector security operations center. Deliver integrated automation, behavior‑based detection, and SIEM content in a regulated environment.
**Expectations**
Deliver production‑ready SOAR playbooks, UEBA rules, and SIEM connectors for Microsoft Sentinel. Collaborate with cross‑functional cybersecurity teams to tune detections, reduce false positives, and maintain system performance aligned with MITRE ATT&CK and Zero‑Trust principles. Provide Tier III support and detailed technical documentation.
**Key Responsibilities**
- Design, develop, test, and deploy SOAR automation playbooks using Azure Logic Apps, Azure Functions, ARM templates, and REST APIs.
- Build automated workflows for alert enrichment, incident triage, response actions, notifications, and case management.
- Integrate Microsoft Sentinel with EDR, IAM, ticketing, email gateways, and firewalls.
- Develop UEBA detection rules, anomaly models, and behavior‑based analytics with KQL.
- Create and maintain analytics rules, parsers, normalization logic, and entity behavior profiles.
- Design custom data connectors, ingestion pipelines, and data transformations.
- Build dashboards, workbooks, hunting queries, and detection‑as‑code assets.
- Tune Sentinel for performance, alert quality, and compliance with security frameworks.
- Develop supporting scripts, APIs, and microservices (Python, PowerShell, .NET).
- Work with DevOps pipelines, CI/CD, GitHub, and Azure DevOps.
- Produce technical documentation, architecture diagrams, runbooks, and SOPs.
- Provide incident reviews and Tier III support as needed.
**Required Skills**
- 3+ years Microsoft Sentinel engineering experience.
- 1+ year SOAR playbook development.
- 1+ year UEBA model and behavioral analytics experience.
- Strong KQL, SIEM analytics, and threat detection engineering.
- Integration of Sentinel with EDR, IAM, firewalls, and ticketing systems.
- Proficiency with Azure services, DevOps pipelines, version control (Git).
- Experience in regulated environments (government, healthcare, etc.).
- Ability to work in a collaborative, multi‑team environment.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Systems, Software Engineering, Cybersecurity, or related field.
- Relevant Microsoft certifications (SC‑200, AZ‑900, AZ‑104, SC‑300, SC‑100) preferred or in progress.