Sentinel Engineer

๐Ÿข avatarrecruit ยท all avatarrecruit jobs
๐Ÿ“ United States
๐Ÿ’ฐ USD 135,000 - 155,000 / annual
๐Ÿ“… Posted 2026-07-23 ยท via Himalayas
๐Ÿท Azure-Sentinel-Engineer,SIEM-Engineering,Detection-Engineering,Cybersecurity-Engineering,Security-Operations,Engineer,Monitoring-Engineer,Microsoft-Sentinel-Analyst,Detection-Engineer,Security-Engineer
Apply on original site โ†—

About this position:

USA | $135k to $155k per annum | Permanent | Remote

Reports To: Head: SIEM Engineering
On-Call: Participation in a major-incident on-call rotation. Activations are infrequent, typically 3 or 4 times a year, and are reserved for significant security incidents requiring engineering support outside normal hours.

Before You Apply: This is a hands-on engineering role. To be considered, you must currently spend 70% or more of your working time in a SIEM engineering role (Sentinel, CrowdStrike).

Job Summary
Our client is looking for a skilled and experienced Sentinel Engineer to join our cybersecurity team. The role covers both sides of the Sentinel platform: integrating log sources, deploying and enhancing data connectors, developing custom connectors where required, and optimising ingestion, and detection engineering, writing and tuning KQL analytics rules, building hunting queries, and translating threat-actor TTPs into detections that catch real attacks with low false-positive rates.

Responsibilities
Primary

- Act as the technical lead for log integration on client onboarding projects โ€” owning the engineering end-to-end, working alongside a project manager who runs the overall programme.

- Scope log integration workstreams, sequence the work, and track technical progress through delivery. Where there is no project manager in the loop โ€” for example, a new log-source type being driven directly with the client โ€” drive the technical engagement yourself, including pushing client infrastructure teams to open firewall rules, fix GPOs and unblock dependencies.

- Research, test and advise clients on audit configuration settings for log sources, to ensure that the right logs flow into Sentinel for threat detection.

- Deploy data connectors and troubleshoot data ingestion, including deployment of Function Apps, customisation and enhancement of Function App code where required, and development of custom log ingestion solutions.

- Research and prototype integrations for unfamiliar log sources โ€” working from vendor documentation, standing up lab instances, generating representative events, validating the end-to-end path into Sentinel, and producing a repeatable template configuration for client deployment.

- Validate log parsing, fix and enhance existing parsers, and develop new parsers.

- Optimise collected logs so the right events are captured and unnecessary events are filtered out, managing consumption and cost.

- Develop and maintain Sentinel analytics rules โ€” scheduled queries, NRT rules, and Fusion/anomaly rules โ€” mapped to MITRE ATT&CK techniques.

- Build and maintain hunting queries and workbooks to support proactive threat hunting and investigations.

- Engage with client cybersecurity professionals on detection strategy, requirements gathering and use-case prioritisation.

- Translate threat intelligence and threat-actor TTPs into deployable detections, including detection-as-code workflows for review, testing and rollout.

Secondary

- Use the team's Azure DevOps repos and pipelines day-to-day โ€” committing code, raising pull requests, and contributing to pipeline content that scales services across multiple clients.

- Sentinel health checks and periodic maintenance, e.g., data connector updates.

- Tune existing analytics rules for false-positive reduction, and integrate applicable changes from upstream rule repositories into the rule base.

- Document solution design and develop technical processes and procedures to enhance the knowledge base and aid standardisation efforts.

- Analyse security logs across the full breadth of client environments to inform parser development and detection authoring.

Qualifications and Experience
Mandatory

- Minimum of 2 years hands-on Sentinel design and implementation experience.

- Minimum of 5 years total cybersecurity experience (engineering, operations or detection โ€” not consulting or advisory).

- Strong proficiency in KQL (Kusto Query La

โ† All remote jobs