- Company Name
- PriceSenz
- Job Title
- Cybersecurity Engineer (SIEM & SOAR)
- Job Description
-
**Job Title:** Cybersecurity Engineer (SIEM & SOAR)
**Role Summary:**
Design, develop, and optimize Microsoft Sentinel-based security operations solutions. Lead work on SIEM, SOAR, UEBA, analytics, and platform integrations; automate playbooks, enhance detection, and streamline incident response with minimal supervision.
**Expectations:**
- Deliver robust, production‑ready Sentinel architecture and automation.
- Reduce noise and false positives in detection rules.
- Provide Tier III support and incident review participation.
- Maintain high‑quality documentation, SOPs, and runbooks.
**Key Responsibilities:**
- Design, code, test, and deploy Azure Logic Apps, Functions, ARM templates, and APIs for Sentinel playbooks.
- Build alert enrichment, triage, response, notifications, and case‑management workflows.
- Integrate Sentinel with EDR, IAM, ticketing, email gateways, and firewalls.
- Create custom UEBA rules, anomaly models, and behavioral analytics.
- Write, tune, and optimize KQL queries for threat hunting and analytics.
- Develop data connectors, ingestion pipelines, dashboards, and workbooks.
- Tune platform performance, noise reduction, and align with MITRE ATT&CK & Zero‑Trust principles.
- Develop supporting scripts/services in Python, PowerShell, .NET, etc.
- Support CI/CD, version control, and IaC practices.
- Produce technical documentation, architecture diagrams, and SOPs.
- Deliver Tier III support and participate in post‑incident reviews.
**Required Skills:**
- Microsoft Sentinel, Azure Logic Apps, Azure Functions, ARM templates, Event Hubs, Key Vault, Entra ID.
- Proficiency in KQL, scripting (Python, PowerShell, .NET), and REST API integrations.
- SIEM/SOAR development, playbook automation, UEBA analytics, incident response.
- Familiarity with MITRE ATT&CK, NIST CSF, Zero‑Trust concepts, and security operations workflows.
- Strong analytical, problem‑solving, and communication abilities.
- Experience with DevOps pipelines (Azure DevOps, GitHub) and IaC.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or related field.
- Minimum 2 years of software/cloud engineering or SIEM‑related experience.
- Certifications (preferred): SC‑200, AZ‑900, AZ‑104, SC‑100, SC‑300.