1

Microsoft Sentinel Architect Jobs (NOW HIRING)

Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and ... Microsoft Sentinel * Azure Log Analytics * Kusto Query Language (KQL) * Azure Logic Apps

Document architectural decisions and create knowledge-transfer materials for client stakeholders ... What You Bring * 4+ years of experience deploying and administering Microsoft Sentinel in ...

New

Ob Architektur, Forensik oder Cloud - unser Cyber‑Security‑Team bringt vielfältige Kompetenzen ... Fundierte Kenntnisse in Microsoft Sentinel und idealerweise Microsoft Defender XDR * Erfahrung in ...

This is a senior-level engineering and architecture role focused on delivering secure, compliant ... Microsoft Sentinel for SIEM/SOAR * Microsoft Defender Suite (Defender for Endpoint, Identity, Cloud ...

Solutions Architect

Greenwood Village, CO · On-site +1

$110K - $210K/yr

Responsibilities Sentinel is looking for a Solutions Architect to join our team. This role is ... Microsoft. Sentinel services customers both nationally and internationally with primary support ...

Solutions Architect

Greenwood Village, CO · On-site +1

$110K - $210K/yr

Sentinel is looking for a Solutions Architect to join our team. This role is tailored for ... Microsoft. Sentinel services customers both nationally and internationally with primary support ...

Solutions Architect

Greenwood Village, CO · On-site +1

$110K - $210K/yr

Responsibilities Sentinel is looking for a Solutions Architect to join our team. This role is ... Microsoft. Sentinel services customers both nationally and internationally with primary support ...

Showing results 21-40

Microsoft Sentinel Architect information

See salary details

$46.5K

$128.8K

$201.5K

How much do microsoft sentinel architect jobs pay per year?

As of Sep 11, 2026, the average yearly pay for microsoft sentinel architect in the United States is $128,756.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,000.00 and $166,000.00 per year, depending on experience, location, and employer.

What does a Microsoft Sentinel Architect do?

A Microsoft Sentinel Architect is responsible for designing, implementing, and managing security information and event management (SIEM) solutions using Microsoft Sentinel. They analyze an organization's security requirements, create scalable architectures, integrate data sources, and develop detection rules and automation workflows. Their goal is to enhance security monitoring, incident detection, and response capabilities within the Microsoft cloud ecosystem. Additionally, they provide best practices, ongoing optimization, and support to ensure the effectiveness of the Sentinel deployment.

What are the key skills and qualifications needed to thrive as a Microsoft Sentinel Architect?

To thrive as a Microsoft Sentinel Architect, you need expertise in cybersecurity, cloud architecture, and SIEM solutions, along with relevant certifications such as Microsoft Certified: Security Operations Analyst Associate. Familiarity with tools like Microsoft Sentinel, Azure platform services, Kusto Query Language (KQL), and automation frameworks is crucial. Strong analytical thinking, problem-solving abilities, and effective communication set candidates apart in this role. These skills ensure robust security monitoring, efficient incident response, and optimal integration of Sentinel within complex enterprise environments.

How does a Microsoft Sentinel Architect typically collaborate with security operations and IT teams?

A Microsoft Sentinel Architect works closely with Security Operations Center (SOC) analysts, IT administrators, and other cybersecurity professionals to design and implement scalable security monitoring solutions. They translate business and security requirements into Sentinel use cases, coordinate with IT teams to integrate data sources, and assist SOC teams in developing effective detection rules and automated incident response procedures. Regular communication and cross-functional teamwork are essential, as architects often lead workshops, provide technical guidance, and ensure the Sentinel environment aligns with the organization's broader security strategy.

What is the difference between Microsoft Sentinel Architect vs Security Engineer?

AspectMicrosoft Sentinel ArchitectSecurity Engineer
CertificationsMicrosoft Certified: Security, Compliance, and Identity Fundamentals, Azure Security Engineer AssociateCompTIA Security+, CISSP, CEH
Work EnvironmentDesigning and implementing security solutions using Microsoft Sentinel in cloud and hybrid environmentsMonitoring, analyzing, and responding to security incidents across various systems
Industry UsagePrimarily in organizations leveraging Microsoft cloud servicesAcross diverse industries with varied security tools and platforms

The Microsoft Sentinel Architect focuses on designing and deploying security solutions using Microsoft Sentinel, while the Security Engineer handles day-to-day security monitoring and incident response across multiple platforms. Both roles require security certifications, but the Architect specializes in cloud security architecture, whereas the Engineer emphasizes operational security tasks.

What are popular job titles related to Microsoft Sentinel Architect jobs?

For Microsoft Sentinel Architect jobs, the most frequently searched job titles are:

Infographic showing various Microsoft Sentinel Architect job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 89% Full Time, 7% Part Time, 1% Temporary, and 2% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $128,756 per year, or $61.9 per hour.

Microsoft Sentinel Subject Matter Expert

Roswell, GA • On-site

2T Consulting
IT Services • 51 - 200 employees

Full-time

This job post has expired 2 days ago. Applications are no longer accepted.


Job description

We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement, optimize, and manage Microsoft Sentinel and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection, incident response, security automation, cloud security, and compliance across enterprise Azure environments.

Roles and Responsibilities
  • Design, implement, configure, and manage Microsoft Sentinel SIEM/SOAR solutions.
  • Integrate security data sources into Azure Log Analytics, including Syslog, CEF, APIs, and threat intelligence feeds.
  • Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards.
  • Develop automated security response workflows using Azure Logic Apps and Microsoft Copilot for Security.
  • Perform threat hunting, incident investigation, detection engineering, and response activities in collaboration with SOC teams.
  • Implement and manage Azure security controls aligned with Zero Trust principles.
  • Configure and secure enterprise Azure environments, including identity, access, monitoring, and security services.
  • Assess vulnerabilities, analyze attacker TTPs, and support remediation and security improvement initiatives.
  • Integrate and manage Microsoft Defender XDR, including Defender for Endpoint, Office 365, Identity, and Cloud Apps.
  • Support cloud security governance, compliance, risk assessments, and audit activities.
  • Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and cloud security initiatives.
  • Develop security standards, operational procedures, and best practices for Sentinel and Azure security services.
  • Collaborate with Security Operations, Cloud Engineering, Identity, Application Security, and Governance teams.
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • 5+ years of cybersecurity experience, including strong hands-on experience with Microsoft Sentinel engineering and administration.
  • Strong expertise in:
    • Microsoft Sentinel
    • Azure Log Analytics
    • Kusto Query Language (KQL)
    • Azure Logic Apps
    • Microsoft Defender XDR
    • Azure Security and Identity Services
    • Microsoft Entra ID
    • Privileged Identity Management (PIM)
    • Conditional Access
    • Security monitoring and incident response
    • CI/CD security and application security scanning
  • Strong understanding of SIEM/SOAR, threat detection, threat hunting, incident response, and security automation.
  • Experience implementing security controls in enterprise Azure environments.
  • Strong knowledge of Zero Trust architecture and cloud security best practices.
Preferred Qualifications
  • Experience with Azure Government / Government Cloud environments.
  • Experience with FISMA, FedRAMP, and NIST security and compliance frameworks.
  • Relevant certifications such as CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Cybersecurity Architect Expert.
  • Experience working with security auditors, compliance teams, and executive stakeholders.