- Company Name
- AMER Technology, Inc.
- Job Title
- Cyber Security Specialist
- Job Description
-
**Job title:** Cyber Security Specialist – Microsoft Sentinel Detection & SOAR Engineer
**Role summary:** Design, develop, test, and maintain Microsoft Sentinel SOAR solutions, UEBA rules, and SIEM content. Build automated playbooks, ingestion pipelines, and detection-as-code assets to reduce alert noise, improve incident response, and align with MITRE ATT&CK and Zero Trust principles. Provide Tier III engineering support and documentation for Sentinel operations.
**Expectations:** Operate independently with limited supervision; own end‑to‑end lifecycle of Sentinel solutions; deliver high‑quality automation, governance, and analytical artifacts; maintain platform performance and compliance standards.
**Key responsibilities**
- Create and deploy Sentinel SOAR playbooks using Azure Logic Apps, Azure Functions, ARM templates, and REST APIs.
- Develop automated workflows for alert enrichment, triage, response actions, notifications, and case management.
- Author UEBA detection rules, behavioral analytics, anomaly models, and KQL hunting queries.
- Build and maintain analytics rules, dashboards, workbooks, data parsers, and detection‑as‑code assets.
- Design custom connectors, ingestion pipelines, and tune SIEM noise levels.
- Write scripts and integrations in Python, PowerShell, .NET, or equivalent.
- Produce technical documentation, runbooks, and SOPs.
- Deliver Tier III Sentinel engineering support and troubleshoot complex issues.
**Required skills**
- Proficiency in Azure services (Logic Apps, Functions, ARM templates).
- Strong scripting/ programming in Python, PowerShell, or .NET.
- Experience designing and implementing SOAR playbooks and UEBA rules.
- Knowledge of SIEM architectures, data ingestion, and analytics.
- Familiarity with MITRE ATT&CK, Zero Trust concepts, and security best practices.
**Required education & certifications**
- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or related field.
- 2+ years of software development or cybersecurity engineering experience.
- Preferred: 3+ years hands‑on Microsoft Sentinel, SOAR, UEBA, and Azure DevOps/CI‑CD.
- Relevant Microsoft security certifications (SC‑200, SC‑300, SC‑100, AZ‑900/104) and experience in regulated environments (government or healthcare) are a plus.