1

Azure Sentinel Siem Engineer Jobs (NOW HIRING)

SIEM Engineer II

Chicago, IL · On-site

$133K - $166K/yr

... Sentinel). * Cribl Development - Support the design and maintenance of Cribl pipelines, including ... Azure, Google Cloud Platform (GCP)) is a plus. * Problem Solving & Growth Mindset - Strong ...

... Sentinel ... and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection ...

Sentinel is already deployed, but this individual will drive the core buildout, integration, and ... Azure SIEM), with deep expertise in log ingestion, integration, data lifecycle management, and ...

Showing results 21-40

Azure Sentinel Siem Engineer information

See salary details

$25

$53

$76

How much do azure sentinel siem engineer jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for azure sentinel siem engineer in the United States is $53.63, according to ZipRecruiter salary data. Most workers in this role earn between $43.27 and $62.26 per hour, depending on experience, location, and employer.

What does an Azure Sentinel SIEM engineer do?

An Azure Sentinel SIEM Engineer is responsible for designing, implementing, and managing security monitoring solutions using Microsoft Azure Sentinel, a cloud-native Security Information and Event Management (SIEM) platform. They configure data connectors, create detection rules, automate incident responses, and analyze security events to identify threats. Their role is critical in helping organizations detect, investigate, and respond to security incidents in real time, ensuring the protection of digital assets within the Azure environment.

What are the key skills and qualifications needed to thrive as an Azure Sentinel SIEM engineer, and why are they important?

To thrive as an Azure Sentinel SIEM Engineer, you need a strong background in cybersecurity, incident response, and security information and event management, typically supported by a degree in computer science or a related field. Experience with Microsoft Azure Sentinel, Kusto Query Language (KQL), and certifications like Microsoft Certified: Security Operations Analyst Associate are highly valued. Analytical thinking, attention to detail, and strong communication skills are critical for investigating threats and collaborating with stakeholders. These skills ensure effective threat detection, timely incident response, and robust protection of organizational assets in a cloud environment.

What are some common challenges faced by Azure Sentinel SIEM engineers and how can they be managed?

Azure Sentinel SIEM Engineers often face challenges such as tuning detection rules to minimize false positives, integrating diverse data sources, and keeping up with evolving security threats. To manage these, it’s important to collaborate closely with security analysts, regularly review and refine analytic rules, and leverage automation for incident response. Additionally, staying updated with Microsoft documentation and engaging with the security community can help address integration and threat detection challenges effectively.

What is the difference between Azure Sentinel Siem Engineer vs Security Analyst?

AspectAzure Sentinel Siem EngineerSecurity Analyst
CertificationsAzure Security, SIEM, Cloud certificationsCompTIA Security+, CISSP, CEH
Work EnvironmentCloud-based SIEM management, security monitoringNetwork, endpoint, and application security analysis
Industry UsageIT, cybersecurity, cloud service providersFinancial, healthcare, government sectors

The Azure Sentinel Siem Engineer focuses on deploying, configuring, and managing Azure Sentinel for security monitoring in cloud environments. In contrast, a Security Analyst performs broader security analysis across various systems, often including incident response and threat detection. While both roles require security certifications and involve security monitoring, the engineer specializes in cloud SIEM tools, whereas the analyst has a more general security oversight role.

What are popular job titles related to Azure Sentinel Siem Engineer jobs?

For Azure Sentinel Siem Engineer jobs, the most frequently searched job titles are:

Microsoft Sentinel Subject Matter Expert

Austell, GA • On-site

2T Consulting
IT Services • 51 - 200 employees

Full-time

This job post has expired 2 days ago. Applications are no longer accepted.


Job description

We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement, optimize, and manage Microsoft Sentinel and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection, incident response, security automation, cloud security, and compliance across enterprise Azure environments.

Roles and Responsibilities
  • Design, implement, configure, and manage Microsoft Sentinel SIEM/SOAR solutions.
  • Integrate security data sources into Azure Log Analytics, including Syslog, CEF, APIs, and threat intelligence feeds.
  • Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards.
  • Develop automated security response workflows using Azure Logic Apps and Microsoft Copilot for Security.
  • Perform threat hunting, incident investigation, detection engineering, and response activities in collaboration with SOC teams.
  • Implement and manage Azure security controls aligned with Zero Trust principles.
  • Configure and secure enterprise Azure environments, including identity, access, monitoring, and security services.
  • Assess vulnerabilities, analyze attacker TTPs, and support remediation and security improvement initiatives.
  • Integrate and manage Microsoft Defender XDR, including Defender for Endpoint, Office 365, Identity, and Cloud Apps.
  • Support cloud security governance, compliance, risk assessments, and audit activities.
  • Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and cloud security initiatives.
  • Develop security standards, operational procedures, and best practices for Sentinel and Azure security services.
  • Collaborate with Security Operations, Cloud Engineering, Identity, Application Security, and Governance teams.
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • 5+ years of cybersecurity experience, including strong hands-on experience with Microsoft Sentinel engineering and administration.
  • Strong expertise in:
    • Microsoft Sentinel
    • Azure Log Analytics
    • Kusto Query Language (KQL)
    • Azure Logic Apps
    • Microsoft Defender XDR
    • Azure Security and Identity Services
    • Microsoft Entra ID
    • Privileged Identity Management (PIM)
    • Conditional Access
    • Security monitoring and incident response
    • CI/CD security and application security scanning
  • Strong understanding of SIEM/SOAR, threat detection, threat hunting, incident response, and security automation.
  • Experience implementing security controls in enterprise Azure environments.
  • Strong knowledge of Zero Trust architecture and cloud security best practices.
Preferred Qualifications
  • Experience with Azure Government / Government Cloud environments.
  • Experience with FISMA, FedRAMP, and NIST security and compliance frameworks.
  • Relevant certifications such as CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Cybersecurity Architect Expert.
  • Experience working with security auditors, compliance teams, and executive stakeholders.