Skip to content
← Back to job listings

Security Engineer ll – Microsoft Sentinel SIEM

cyderes · Bengaluru, Karnataka, India

CybersecurityExternal listingfull-time3 days ago

About The Role

We Help the World Be Everyday Ready™

Today's threatscape is relentless. So are we. At Cyderes, we build practical Identity & Access Management (IAM), Exposure Management, and risk programs, helping organizations stop active threats fast with Managed Detection & Response (MDR) that integrates with existing tools. Powering it all is Meridian, our entity fabric that connects identities, assets, and access into one trusted reality. Augmented by AI and driven by seasoned operators, our tireless global team arms organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way.

🏆 Great Place to Work® Certified™ | United States | Canada | United Kingdom | India

About the Job

The Security Engineer ll – Microsoft Sentinel & Defender XDR plays a critical engineering role within Cyderes' Managed Sentinel SIEM and MDR services.

You will go beyond basic platform administration. The Security Engineer ll is responsible for detection engineering, platform optimization, onboarding lifecycle execution, and Defender XDR integration. You will be a trusted technical resource to clients, ensuring you configure, improve, and improve their Microsoft security ecosystem against evolving threats.

You will represent and promote the Cyderes brand through collaboration, and delivery that meets client expectations.

You will report to Senior Manager, Managed Platforms.

Responsibilities

  • Administer and maintain Microsoft Sentinel and Defender XDR environments across multiple managed client tenants, ensuring platform health and availability.
  • Support platform intake and provide coverage during Eastern Time business hours, including troubleshooting of platform and telemetry issues.
  • Onboard and integrate new log sources and security data into Sentinel, validating connectivity, parsing, normalisation, data quality, and entity mapping.
  • Maintain, and tune Sentinel detection rules using KQL, including Scheduled, NRT, and Fusion analytics, with a focus on reducing false positives and improving alert fidelity.
  • Map detection use cases to MITRE ATT&CK and contribute to reusable detection, threat-hunting, dashboards, workbooks, and reporting libraries.
  • Monitor Sentinel and Defender XDR alerts and perform Tier 2 investigation and escalation support for MDR/SOC teams.
  • Develop SOAR automation using Azure Logic Apps, including automated response actions such as device isolation, user disablement, IP blocking, and ticket creation.
  • Monitor ingestion volumes, connector health, and data quality while identifying opportunities for platform standardisation, performance improvement, and cost optimization across the MSSP environment.
  • Develop runbooks, SOPs, onboarding documentation, and detection standards while staying current with Microsoft security platform capabilities and industry best practices.

Requirements

  • Diploma or Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience.
  • 3–5 years of experience in cybersecurity, SOC, security engineering, or related roles, with at least 2 years of hands-on Microsoft Sentinel experience.
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Azure Log Analytics, and KQL.
  • Experience working in an MSSP, MDR, or customer-facing security environment with multi-tenant Azure environments; Azure Lighthouse experience.
  • Experience with Windows and Linux logs, Entra ID, networking fundamentals, authentication/authorization, and common security telemetry.
  • Experience with Azure Logic Apps, REST APIs, and scripting using PowerShell or Python.
  • Working knowledge of the MITRE ATT&CK framework and MDR/SOC operational workflows.
  • We prefer relevant certifications such as SC-200, AZ-500, SC-100, Security+, or Microsoft Defender certifications.
  • Documentation, with the ability to balance daily platform operations, detection engineering, and continuous improvement.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing