哨兵工程师
Sentinel Engineer
职位信息:
美国 | 每年135,000至155,000美元 | 正式职位 | 远程办公
汇报对象:SIEM工程负责人
值班:参与重大事件的值班轮班。触发次数较少,通常每年3到4次,仅用于需要工程支持的严重安全事件,且发生在正常工作时间之外。
申请前须知:这是一个需要亲自操作的工程岗位。申请者必须目前在SIEM工程岗位上投入70%或更多工作时间(如Sentinel、CrowdStrike)。
职位简介
我们的客户正在寻找一名有技能和经验的Sentinel工程师加入我们的网络安全团队。该职位涵盖Sentinel平台的两个方面:集成日志源、部署和增强数据连接器、在需要时开发自定义连接器,以及优化数据采集和检测工程,编写和调整KQL分析规则,构建狩猎查询,并将威胁行为者的TTPs转化为能有效捕捉真实攻击且误报率低的检测方案。
职责
主要职责
- 作为客户上线项目中日志集成的技术负责人——负责整个工程流程,与负责整体项目的项目经理合作。
- 确定日志集成的工作流,安排工作顺序,并跟踪技术进展直至交付。如果没有项目经理参与——例如,直接由客户推动的新日志源类型——则自行主导技术对接,包括推动客户基础设施团队开放防火墙规则、修复GPO并解除依赖关系。
- 研究、测试并建议客户对日志源的审计配置设置,以确保正确的日志流入Sentinel用于威胁检测。
- 部署数据连接器并排查数据采集问题,包括部署Function Apps,根据需要定制和增强Function App代码,以及开发自定义的日志采集解决方案。
- 研究并原型化不熟悉日志源的集成——从供应商文档出发,搭建实验室实例,生成代表性事件,验证端到端路径进入Sentinel,并为客户提供可重复使用的模板配置。
- 验证日志解析,修复和增强现有解析器,并开发新的解析器。
- 优化收集到的日志,确保捕获正确的事件并过滤掉不必要的事件,管理使用量和成本。
- 开发和维护S
查看英文原文
About this position:
USA | $135k to $155k per annum | Permanent | Remote
Reports To: Head: SIEM Engineering
On-Call: Participation in a major-incident on-call rotation. Activations are infrequent, typically 3 or 4 times a year, and are reserved for significant security incidents requiring engineering support outside normal hours.
Before You Apply: This is a hands-on engineering role. To be considered, you must currently spend 70% or more of your working time in a SIEM engineering role (Sentinel, CrowdStrike).
Job Summary
Our client is looking for a skilled and experienced Sentinel Engineer to join our cybersecurity team. The role covers both sides of the Sentinel platform: integrating log sources, deploying and enhancing data connectors, developing custom connectors where required, and optimising ingestion, and detection engineering, writing and tuning KQL analytics rules, building hunting queries, and translating threat-actor TTPs into detections that catch real attacks with low false-positive rates.
Responsibilities
Primary
- Act as the technical lead for log integration on client onboarding projects — owning the engineering end-to-end, working alongside a project manager who runs the overall programme.
- Scope log integration workstreams, sequence the work, and track technical progress through delivery. Where there is no project manager in the loop — for example, a new log-source type being driven directly with the client — drive the technical engagement yourself, including pushing client infrastructure teams to open firewall rules, fix GPOs and unblock dependencies.
- Research, test and advise clients on audit configuration settings for log sources, to ensure that the right logs flow into Sentinel for threat detection.
- Deploy data connectors and troubleshoot data ingestion, including deployment of Function Apps, customisation and enhancement of Function App code where required, and development of custom log ingestion solutions.
- Research and prototype integrations for unfamiliar log sources — working from vendor documentation, standing up lab instances, generating representative events, validating the end-to-end path into Sentinel, and producing a repeatable template configuration for client deployment.
- Validate log parsing, fix and enhance existing parsers, and develop new parsers.
- Optimise collected logs so the right events are captured and unnecessary events are filtered out, managing consumption and cost.
- Develop and maintain Sentinel analytics rules — scheduled queries, NRT rules, and Fusion/anomaly rules — mapped to MITRE ATT&CK techniques.
- Build and maintain hunting queries and workbooks to support proactive threat hunting and investigations.
- Engage with client cybersecurity professionals on detection strategy, requirements gathering and use-case prioritisation.
- Translate threat intelligence and threat-actor TTPs into deployable detections, including detection-as-code workflows for review, testing and rollout.
Secondary
- Use the team's Azure DevOps repos and pipelines day-to-day — committing code, raising pull requests, and contributing to pipeline content that scales services across multiple clients.
- Sentinel health checks and periodic maintenance, e.g., data connector updates.
- Tune existing analytics rules for false-positive reduction, and integrate applicable changes from upstream rule repositories into the rule base.
- Document solution design and develop technical processes and procedures to enhance the knowledge base and aid standardisation efforts.
- Analyse security logs across the full breadth of client environments to inform parser development and detection authoring.
Qualifications and Experience
Mandatory
- Minimum of 2 years hands-on Sentinel design and implementation experience.
- Minimum of 5 years total cybersecurity experience (engineering, operations or detection — not consulting or advisory).
- Strong proficiency in KQL (Kusto Query Language).
- Hands-on Linux system administration experience.
- Solid networking fundamentals.
- Experience deploying and managing Azure Arc and AMA, including DCRs.
- Experience with syslog collection architectures and Windows event collection.
- Experience operating in multi-tenant Azure environments.
- Working knowledge of Microsoft Entra ID and Active Directory logging.
- Solid experience working with security logs across multiple domains and product types.
- Experience with Microsoft Defender XDR and Sentinel–Defender integration.
- Familiarity with Sentinel content surface (Content Hub, analytics rules, workbooks, watchlists, threat intelligence connectors).
- Strong understanding of the threat landscape and MITRE ATT&CK.
- Demonstrable detection-engineering experience.
- Proficiency in PowerShell/Python scripting.
- Comfortable with Git workflows and infrastructure-as-code.
- Experience with detection-as-code workflows.
- Excellent problem-solving skills and communication abilities.
- Ability to manage multiple concurrent client engagements.
Nice to Have
- Familiarity with ASIM.
- Experience with Codeless Connector Framework (CCF).
- Experience integrating with REST APIs.
- Experience setting up/administering Azure DevOps.
- Microsoft certifications (SC-200, AZ-104, AZ-500, SC-100).
- Hands-on incident response experience.
- Familiarity with Sigma rules.
- Penetration testing background.
- Experience with Cribl Stream.
Personal Qualities
- Deeply knowledgeable and hands-on.
- Trusted to own work end-to-end.
- Go-getter mindset with initiative.
- Thorough and proactive.
- Client-ready and confident.
- Strong prioritiser in multi-project environments.
- Quality-focused, avoids quick fixes.
- Willing to put in discretionary effort when needed.
Originally posted on Himalayas