Integrity360
Integrity360
201 – 500 Employees
ConsultingHealthcareInsurance
Integrity360 is an independent cybersecurity and PCI specialist serving organizations across Europe. Its teams provide managed security services, consulting, penetration testing, incident response, compliance support, and managed detection and response to help businesses strengthen resilience across their networks, infrastructure, and information. The company operates five Security Operations Centres across Europe and South Africa, delivering continuous monitoring and support for identifying and addressing cyber threats. Integrity360’s work spans security operations, testing, incident management, and regulatory compliance, creating opportunities for professionals working across cybersecurity consulting and managed protection services.

Microsoft Security Engineer Sentinel and Defender XDR Lithuania Remote

Microsoft Security Engineer delivering Sentinel and Defender XDR onboarding for Integrity360’s managed security services. The role covers client integrations, detection tuning, technical documentation, and SOC handover.

Description

  • Lead complete onboarding of client Microsoft Sentinel environments into the MSSP service
  • Set up Sentinel workspaces, content solutions, data connectors, analytics and automation rules, watchlists, and workbooks
  • Conduct technical discovery sessions to assess log sources, connectivity, data volumes, retention, dependencies, and priorities
  • Connect Microsoft, third-party, cloud, network, identity, and application log sources through Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF, and custom connectors
  • Design and apply filtering and transformation methods that improve signal quality and manage ingestion costs
  • Verify ingestion, parsing, field mapping, timestamps, service health, and coverage while resolving issues across source systems and Azure services
  • Refine analytics rules, alert logic, and incident creation in partnership with SOC and detection engineering teams
  • Onboard Microsoft Defender XDR workloads, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps
  • Create high-level designs, implementation plans, configuration records, test evidence, operational runbooks, and handover materials
  • Work with clients, project managers, architects, SOC analysts, and service teams to manage dependencies, risks, actions, and transition readiness
  • Follow engineering standards, peer-review practices, and change control while improving onboarding templates and internal procedures
  • Provide troubleshooting and remediation support during onboarding and early-life service support
  • Travel occasionally to support client delivery

Requirements

  • Demonstrated experience deploying, configuring, or supporting Microsoft Sentinel in production or customer environments
  • Practical knowledge of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection methods
  • Strong Kusto Query Language skills for data validation, troubleshooting, investigations, and detection tuning
  • Experience connecting and troubleshooting log sources across Microsoft 365, Azure, endpoints, identity, networks, security platforms, and third-party systems
  • Understanding of ingestion filtering, data transformation, parsing, normalization, retention, and the cost implications of security telemetry
  • Experience producing technical designs and delivery documentation, including HLDs, implementation plans, test records, and operational handover materials
  • Working knowledge of Microsoft Defender XDR and its integration with Microsoft Sentinel
  • Understanding of SIEM operations, detection engineering, incident workflows, and managed security service requirements
  • Strong troubleshooting ability across Azure, APIs, identity, networking, and data collection components
  • Clear written and verbal communication with technical and non-technical client stakeholders
  • Ability to manage assigned responsibilities independently while working with project, architecture, SOC, and service teams
  • Experience in an MSSP, MDR provider, Security Operations Centre, or security-focused professional services environment is desirable
  • Experience with custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is desirable
  • Experience using DevOps pipelines and source control for Microsoft Sentinel content, configuration, and deployments is desirable
  • Knowledge of detection as code, infrastructure as code, and automation tools such as Bicep, ARM templates, Terraform, PowerShell, Azure CLI, Logic Apps, or APIs is desirable
  • Knowledge of Microsoft Sentinel repositories, content management, and repeatable multi-customer deployment approaches is desirable
  • Experience integrating Microsoft security services across tenants, subscriptions, or delegated administration models such as Azure Lighthouse is desirable
  • Familiarity with MITRE ATT&CK is desirable
  • Microsoft security certifications such as SC-200, AZ-500/SC-500, or SC-100 are desirable but not required

Benefits

  • Opportunities for learning, professional development, and career progression
  • Training and certification support focused on Microsoft security technologies
  • Guidance from an experienced team
  • Occasional travel opportunities supporting client delivery

Related Jobs