The Senior - Cyber Transformation role involves designing, deploying, and managing Microsoft Sentinel SIEM solutions, and supporting threat hunting activities using advanced KQL techniques.
Requirements
- Design, deploy, and manage Microsoft Sentinel SIEM solutions
- Onboard and normalize log sources
- Configure data connectors, custom log ingestion, and parsers
- Optimize data retention, cost management, and performance
- Develop and optimize KQL queries
- Create and maintain analytic rules, scheduled queries, and near real-time detections
- Tune alerts to reduce false positives and improve signal-to-noise ratio
- Support threat hunting activities using advanced KQL techniques
- Build and enhance workbooks, dashboards, and visualizations
- Design and maintain SOAR playbooks using Logic Apps
- Integrate Sentinel with security tools
- Participate in incident investigation and post-incident reviews