Azure Sentinel Architect

·
Full time
Location: Manchester
· ·
Category: IT & Technology
Job Description

Job Summary: We are seeking a talented Azure Sentinel Architect with 2-5 years of experience to design, implement, and optimize our customers' Azure Sentinel-based Security Information and Event Management (SIEM) systems. As an Azure Sentinel Architect, you will be responsible for developing a comprehensive security strategy, defining architecture and policies, integrating and optimizing threat detection, and enabling advanced security monitoring to ensure our customer's digital assets remain secure from cyber threats. You'll work collaboratively with cybersecurity engineers and analysts, IT teams, and other stakeholders to assess security needs of our clients, configure Sentinel to address them, and continuously adapt our systems to emerging threats. This is a hybrid role which may require travel to client locations.

Key Responsibilities:

Design and Implementation Lead the design and implementation of Azure Sentinel to build a robust security monitoring and alerting system. Architect an Azure Sentinel solution to enhance security posture through Real Time threat detection, investigation, and response. Design custom dashboards, workbooks, and automated workflows to streamline security monitoring. Configuration and Optimization Configure and fine-tune Azure Sentinel rules, connectors, and playbooks to optimize threat detection and response capabilities. Ensure scalability and performance by optimizing Sentinel resources, data connectors, and data ingestion pipelines. Develop policies and procedures to ensure Azure Sentinel configuration aligns with industry best practices and compliance standards. Security Analysis and Threat Detection Collaborate with security analysts to implement effective use cases and threat hunting scenarios within Azure Sentinel. Develop and manage custom queries using KQL (Kusto Query Language) to identify potential security incidents and perform forensic analysis. Set up, manage, and refine automated incident response playbooks for efficient response to threats and alerts. Integrations and Automations Integrate Azure Sentinel with other security tools and platforms, such as Microsoft Defender, Entra ID, and third-party security systems. Implement SOAR (Security Orchestration, Automation, and Response) functionalities to enhance incident response times. Ensure seamless integration with IT infrastructure and continuous monitoring across cloud, hybrid, and on-premises environments. Documentation and Training Develop comprehensive documentation for Azure Sentinel designs, configurations, playbooks, and workflows. Provide training and guidance to security team members on Azure Sentinel's use and capabilities. Ensure the knowledge transfer and documentation of procedures for incident response, monitoring, and alert management. Continuous Improvement Regularly review and refine security policies, incident response playbooks, and Sentinel configurations based on the latest threat landscape. Stay current with Azure Sentinel updates, new connectors, and best practices for cybersecurity and compliance. Collaborate with IT teams to improve monitoring coverage and overall security posture.

Required Skills and Experience: Experience: Minimum 5 years of experience in cybersecurity, with at least 2 years focused on Azure Sentinel and/or Microsoft Azure Security. Strong experience in SIEM design, implementation, and administration. Strong problem-solving skills and analytical mindset with the ability to work under pressure. Excellent communication skills to collaborate with both technical and non-technical stakeholders. Technical Skills: Proficiency in Kusto Query Language (KQL) for Sentinel query writing.

#J-18808-Ljbffr

Recent Jobs

London (On site) · Full time

Are you a smart, driven professional who takes pride in making a difference in local communities? Turner & Townsend’s Real Estate division is experiencing significant growth and we’re looking for an experienced industry professional with health project experience to join our high-performing and collaborative Project Management team. Why Join Us? Impactful Work: Contribute to social [...]Read More... from Assistant Project Manager – Healthcare See details

Chasetown (On site) · Full time

My client, Autosmart International are a manufacturing success story! Site Operations Manager – leading fast-paced manufacturing and warehousing About Our Client Autosmart International is a manufacturing success story, leading the field in vehicle cleaning products. We are the No.1 choice of automotive trade customers across the UK. We have doubled in size in the last [...]Read More... from Site Operations Manager See details

London (On site) · Full time

CSS are looking for an experienced duty officer to join our client’s team who are a local council responsible for all areas within the Tendering district. Working hours: All shifts are 8 hours long with various start times available: Monday to Friday – start times between 6AM – 3PM Saturday & Sunday – 6AM – [...]Read More... from Duty Officer See details