Integrity360
Integrity360
201 – 500 Employees
ConsultingHealthcareInsurance
Integrity360 is an independent cybersecurity and PCI specialist serving organizations across Europe. Its teams provide managed security services, consulting, penetration testing, incident response, compliance support, and managed detection and response to help businesses strengthen resilience across their networks, infrastructure, and information. The company operates five Security Operations Centres across Europe and South Africa, delivering continuous monitoring and support for identifying and addressing cyber threats. Integrity360’s work spans security operations, testing, incident management, and regulatory compliance, creating opportunities for professionals working across cybersecurity consulting and managed protection services.

Microsoft Security Engineer - Rome Hybrid

Onboard Microsoft Sentinel and Defender XDR for Integrity360’s managed cybersecurity services. Deliver client deployments from technical discovery through testing, documentation, and SOC handover.

Description

  • Lead end-to-end onboarding of client Microsoft Sentinel environments into the MSSP service
  • Configure Sentinel workspaces, content solutions, data connectors, analytics and automation rules, watchlists, and workbooks
  • Conduct technical discovery sessions covering log sources, connectivity, data volumes, retention, dependencies, and priorities
  • Onboard Microsoft, third-party, cloud, network, identity, and application log sources through supported collection methods
  • Design and implement filtering and transformation approaches that improve signal quality and manage ingestion costs
  • Verify ingestion, parsing, field mapping, timestamps, health, and coverage while resolving technical issues
  • Tune analytics rules, alert logic, and incident creation in partnership with SOC and detection engineering teams
  • Integrate Microsoft Defender XDR workloads, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps
  • Create high-level designs, implementation plans, configuration records, test evidence, operational runbooks, and handover documentation
  • Coordinate delivery with clients, project managers, architects, SOC analysts, and service teams
  • Follow engineering standards, peer-review practices, and change-control procedures while improving onboarding templates and processes
  • Provide troubleshooting and remediation support during onboarding and early-life service support
  • Travel occasionally to support client delivery
  • Manage onboarding from discovery and design through implementation, testing, documentation, and handover while reporting to the Head of Cloud Security & Microsoft Security Services

Requirements

  • Practical experience deploying, configuring, or supporting Microsoft Sentinel in production or customer environments
  • Working knowledge of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection patterns
  • Strong proficiency with Kusto Query Language
  • Experience onboarding and troubleshooting log sources across Microsoft 365, Azure, endpoints, identity, networks, security platforms, and third-party systems
  • Understanding of ingestion filtering, data transformation, parsing, normalization, retention, and the security telemetry cost implications
  • Experience producing technical designs and delivery documentation, including HLDs, implementation plans, test records, and operational handover materials
  • Working knowledge of Microsoft Defender XDR and its integration with Microsoft Sentinel
  • Understanding of SIEM operations, detection engineering principles, incident workflows, and managed security service requirements
  • Strong troubleshooting ability across Azure, APIs, identity, networking, and data collection components
  • Clear written and verbal communication skills when working with technical and non-technical client stakeholders
  • Ability to manage assigned work independently while collaborating with project, architecture, SOC, and service teams
  • Experience in an MSSP, MDR provider, Security Operations Centre, or security-focused professional services team is preferred
  • Experience with custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is preferred
  • Experience with DevOps pipelines, source control, detection as code, infrastructure as code, and automation is preferred
  • Familiarity with MITRE ATT&CK is preferred
  • Microsoft security certifications such as SC-200, AZ-500/SC-500, or SC-100 are desirable but not required

Benefits

  • Opportunities for learning, professional development, and career progression
  • Access to training and certification opportunities across Microsoft security technologies
  • Support from an experienced team

Related Jobs

Knowtion Health

Remote Talent Acquisition Manager

Knowtion Health

Oversee recruiting systems, requisitions, analytics, and contingent workforce operations at Knowtion Health. Help support scalable hiring processes for a growing healthcare company.

Open