Integrity360
Integrity360
201 – 500 Employees
ConsultingHealthcareInsurance
Integrity360 is an independent cybersecurity and PCI specialist serving organizations across Europe. Its teams provide managed security services, consulting, penetration testing, incident response, compliance support, and managed detection and response to help businesses strengthen resilience across their networks, infrastructure, and information. The company operates five Security Operations Centres across Europe and South Africa, delivering continuous monitoring and support for identifying and addressing cyber threats. Integrity360’s work spans security operations, testing, incident management, and regulatory compliance, creating opportunities for professionals working across cybersecurity consulting and managed protection services.

Security Engineer – Microsoft Sentinel & Defender XDR (Hybrid, Spain)

Join Integrity360 as a Microsoft Security Engineer delivering Sentinel and Defender XDR onboarding for managed cybersecurity services. Lead client implementations, detection tuning, technical documentation, and handovers to the SOC.

Description

  • Onboard clients to a managed security service centered on Microsoft Sentinel
  • Configure and integrate Microsoft Sentinel environments
  • Onboard, test, and validate security log sources
  • Prepare deployments for monitoring and operational handover to the Security Operations Centre
  • Configure Sentinel workspaces, content solutions, data connectors, analytics rules, automation rules, watchlists, and workbooks
  • Lead technical discovery sessions covering log sources, connectivity, data volumes, retention, dependencies, and priorities
  • Connect Microsoft, third-party, cloud, network, identity, and application log sources using Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF, and custom connectors
  • Design and implement data filtering and transformation processes
  • Validate ingestion, parsing, field mapping, timestamps, platform health, and coverage while resolving issues
  • Tune analytics rules, alert logic, and incident creation with SOC and detection engineering teams
  • Onboard and integrate Microsoft Defender XDR workloads
  • Create high-level designs, implementation plans, configuration records, test evidence, runbooks, and handover documentation
  • Coordinate delivery with clients, project managers, architects, SOC analysts, and service teams
  • Follow engineering standards, peer review, and change control while improving onboarding templates and procedures
  • Provide troubleshooting and remediation support during onboarding and early-life service support
  • Own onboarding delivery from discovery and design through implementation, testing, documentation, and handover

Requirements

  • Production or customer-facing experience deploying, configuring, or supporting Microsoft Sentinel
  • Practical knowledge of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection patterns
  • Strong proficiency with Kusto Query Language
  • Experience onboarding and troubleshooting log sources across Microsoft 365, Azure, endpoints, identity, network, security, and third-party platforms
  • Understanding of ingestion filtering, data transformation, parsing, normalization, retention, and the security telemetry cost implications
  • Experience producing technical designs and delivery materials, including HLDs, implementation plans, test records, and operational handover documentation
  • Working knowledge of Microsoft Defender XDR and integration of its workloads with Microsoft Sentinel
  • Understanding of SIEM operations, detection engineering, incident workflows, and managed security service requirements
  • Strong troubleshooting ability across Azure, APIs, identity, networking, and data collection components
  • Clear written and verbal communication with technical and non-technical client stakeholders
  • Ability to manage assigned work independently while collaborating with project, architecture, SOC, and service teams
  • Willingness to travel occasionally when required
  • MSSP, MDR, Security Operations Centre, or security-focused professional services experience is desirable
  • Experience with custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is desirable
  • Experience with DevOps pipelines and source control for Microsoft Sentinel content is desirable
  • Experience with detection as code, infrastructure as code, and automation using Bicep, ARM templates, Terraform, PowerShell, Azure CLI, Logic Apps, or APIs is desirable
  • Familiarity with Microsoft Sentinel repositories, content management, and multi-customer deployment patterns is desirable
  • Experience integrating Microsoft security services across tenants, subscriptions, or delegated administration models such as Azure Lighthouse is desirable
  • Familiarity with MITRE ATT&CK is desirable
  • Microsoft SC-200, AZ-500/SC-500, SC-100, relevant Microsoft Applied Skills, or other relevant security and cloud certifications are beneficial but not essential

Benefits

  • Opportunities for learning, professional development, and career progression
  • Access to training and certification opportunities across Microsoft security technologies
  • Guidance and collaboration from an experienced team

Related Jobs