Integrity360
Integrity360
201 – 500 Employees
ConsultingHealthcareInsurance
Integrity360 is an independent cybersecurity and PCI specialist serving organizations across Europe. Its teams provide managed security services, consulting, penetration testing, incident response, compliance support, and managed detection and response to help businesses strengthen resilience across their networks, infrastructure, and information. The company operates five Security Operations Centres across Europe and South Africa, delivering continuous monitoring and support for identifying and addressing cyber threats. Integrity360’s work spans security operations, testing, incident management, and regulatory compliance, creating opportunities for professionals working across cybersecurity consulting and managed protection services.

Microsoft Sentinel Security Engineer (Remote Ukraine)

Onboard Microsoft Sentinel and Defender XDR for Integrity360’s managed cybersecurity services. Lead client discovery, configuration, validation, tuning, documentation, and SOC handover.

Description

  • Lead end-to-end onboarding of client Microsoft Sentinel environments into the MSSP service
  • Configure Sentinel workspaces, content solutions, data connectors, analytics rules, automation rules, watchlists, and workbooks
  • Conduct technical discovery sessions covering log sources, connectivity, data volumes, retention, dependencies, and priorities
  • Onboard Microsoft, third-party, cloud, network, identity, and application log sources using Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF, and custom connectors
  • Design and implement data filtering and transformation to improve signal quality and manage ingestion costs
  • Validate ingestion, parsing, field mapping, timestamps, health, and coverage while troubleshooting source, collector, network, and Azure issues
  • Tune analytics rules, alert logic, and incident generation with SOC and detection engineering teams
  • Onboard and integrate Microsoft Defender XDR workloads, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps
  • Create high-level designs, implementation plans, configuration records, test evidence, operational runbooks, and handover documentation
  • Coordinate with clients, project managers, architects, SOC analysts, and service teams on dependencies, risks, actions, and service transition readiness
  • Apply engineering standards, peer review, and change control while improving onboarding templates, technical patterns, and internal procedures
  • Support troubleshooting and remediation during onboarding and early-life support
  • Travel occasionally when required for client delivery
  • Manage assigned onboarding work from discovery and design through implementation, testing, documentation, and handover
  • Report to the Head of Cloud Security & Microsoft Security Services

Requirements

  • Hands-on experience deploying, configuring, or supporting Microsoft Sentinel in production or customer environments
  • Practical knowledge of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection patterns
  • Strong Kusto Query Language skills
  • Experience onboarding and troubleshooting log sources across Microsoft 365, Azure, endpoints, identity, network, security, and third-party platforms
  • Understanding of ingestion filtering, data transformation, parsing, normalization, retention, and security telemetry costs
  • Experience producing technical designs and delivery documentation, including HLDs, implementation plans, test records, and operational handover materials
  • Working knowledge of Microsoft Defender XDR and its integration with Microsoft Sentinel
  • Understanding of SIEM operations, detection engineering, incident workflows, and managed security service requirements
  • Strong troubleshooting abilities across Azure, APIs, identity, networking, and data collection components
  • Clear written and verbal communication skills with technical and non-technical client stakeholders
  • Ability to manage assigned work independently while collaborating with project, architecture, SOC, and service teams
  • Experience in an MSSP, MDR provider, Security Operations Centre, or security-focused professional services team is desirable
  • Experience with custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is desirable
  • Experience with DevOps pipelines, source control, detection as code, infrastructure as code, and automation is desirable
  • Knowledge of Microsoft Sentinel repositories, content management, and multi-customer deployment patterns is desirable
  • Experience integrating Microsoft security services across tenants, subscriptions, or delegated administration models is desirable
  • Familiarity with MITRE ATT&CK is desirable
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) is desirable
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500/SC-500) is desirable
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) is desirable
  • Relevant Microsoft Applied Skills or other relevant security or cloud certifications are beneficial but not essential

Benefits

  • Opportunities for learning, professional development, and career progression
  • Access to training and certification opportunities across Microsoft security technologies
  • Support from an experienced team

Related Jobs