Integrity360
Integrity360
Integrity360 este o companie independentă de securitate cibernetică și specialistă în PCI, care deservește organizații din întreaga Europă. Echipele sale oferă servicii de securitate gestionată, consultanță, teste de penetrare, răspuns la incidente, asistență pentru conformitate, precum și servicii gestionate de detectare și răspuns, ajutând companiile să își consolideze reziliența rețelelor, infrastructurii și informațiilor. Compania operează cinci centre de operațiuni de securitate în Europa și Africa de Sud, furnizând monitorizare și asistență continuă pentru identificarea și remedierea amenințărilor cibernetice. Activitatea Integrity360 acoperă operațiunile de securitate, testarea, gestionarea incidentelor și conformitatea cu reglementările, oferind oportunități profesioniștilor din consultanța în securitate cibernetică și serviciile de protecție gestionată.

Security Engineer – Microsoft Sentinel & Defender XDR (Hybrid, Spain)

Join Integrity360 as a Microsoft Security Engineer delivering Sentinel and Defender XDR onboarding for managed cybersecurity services. Lead client implementations, detection tuning, technical documentation, and handovers to the SOC.

Descriere

  • Onboard clients to a managed security service centered on Microsoft Sentinel
  • Configure and integrate Microsoft Sentinel environments
  • Onboard, test, and validate security log sources
  • Prepare deployments for monitoring and operational handover to the Security Operations Centre
  • Configure Sentinel workspaces, content solutions, data connectors, analytics rules, automation rules, watchlists, and workbooks
  • Lead technical discovery sessions covering log sources, connectivity, data volumes, retention, dependencies, and priorities
  • Connect Microsoft, third-party, cloud, network, identity, and application log sources using Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF, and custom connectors
  • Design and implement data filtering and transformation processes
  • Validate ingestion, parsing, field mapping, timestamps, platform health, and coverage while resolving issues
  • Tune analytics rules, alert logic, and incident creation with SOC and detection engineering teams
  • Onboard and integrate Microsoft Defender XDR workloads
  • Create high-level designs, implementation plans, configuration records, test evidence, runbooks, and handover documentation
  • Coordinate delivery with clients, project managers, architects, SOC analysts, and service teams
  • Follow engineering standards, peer review, and change control while improving onboarding templates and procedures
  • Provide troubleshooting and remediation support during onboarding and early-life service support
  • Own onboarding delivery from discovery and design through implementation, testing, documentation, and handover

Cerințe

  • Production or customer-facing experience deploying, configuring, or supporting Microsoft Sentinel
  • Practical knowledge of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog, and CEF collection patterns
  • Strong proficiency with Kusto Query Language
  • Experience onboarding and troubleshooting log sources across Microsoft 365, Azure, endpoints, identity, network, security, and third-party platforms
  • Understanding of ingestion filtering, data transformation, parsing, normalization, retention, and the security telemetry cost implications
  • Experience producing technical designs and delivery materials, including HLDs, implementation plans, test records, and operational handover documentation
  • Working knowledge of Microsoft Defender XDR and integration of its workloads with Microsoft Sentinel
  • Understanding of SIEM operations, detection engineering, incident workflows, and managed security service requirements
  • Strong troubleshooting ability across Azure, APIs, identity, networking, and data collection components
  • Clear written and verbal communication with technical and non-technical client stakeholders
  • Ability to manage assigned work independently while collaborating with project, architecture, SOC, and service teams
  • Willingness to travel occasionally when required
  • MSSP, MDR, Security Operations Centre, or security-focused professional services experience is desirable
  • Experience with custom log parsers, KQL functions, ASIM-compatible content, or normalization patterns is desirable
  • Experience with DevOps pipelines and source control for Microsoft Sentinel content is desirable
  • Experience with detection as code, infrastructure as code, and automation using Bicep, ARM templates, Terraform, PowerShell, Azure CLI, Logic Apps, or APIs is desirable
  • Familiarity with Microsoft Sentinel repositories, content management, and multi-customer deployment patterns is desirable
  • Experience integrating Microsoft security services across tenants, subscriptions, or delegated administration models such as Azure Lighthouse is desirable
  • Familiarity with MITRE ATT&CK is desirable
  • Microsoft SC-200, AZ-500/SC-500, SC-100, relevant Microsoft Applied Skills, or other relevant security and cloud certifications are beneficial but not essential

Beneficii

  • Opportunities for learning, professional development, and career progression
  • Access to training and certification opportunities across Microsoft security technologies
  • Guidance and collaboration from an experienced team

Locuri de muncă similare