1

Sentinel Siem Jobs in Georgia (NOW HIRING)

We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement ... The role will focus on SIEM/SOAR engineering, threat detection, incident response, security ...

next page

Showing results 1-20

Sentinel Siem information

What is a Sentinel SIEM?

Sentinel SIEM refers to Microsoft Sentinel, a cloud-native security information and event management (SIEM) solution. It helps organizations detect, investigate, and respond to security threats across their entire enterprise by collecting and analyzing data from various sources. Sentinel SIEM provides advanced threat detection, automated response, and comprehensive visibility into security events, making it easier for security teams to protect their environments. Its integration with Microsoft Azure and other platforms enables scalable and intelligent security operations.

What are the key skills and qualifications needed to thrive as a Sentinel SIEM specialist?

To thrive as a Sentinel SIEM Specialist, you need a solid understanding of cybersecurity principles, threat analysis, and experience with security incident and event management, often supported by a degree in information security or related certifications like Microsoft Certified: Security Operations Analyst Associate. Proficiency with Microsoft Sentinel, Kusto Query Language (KQL), and familiarity with security orchestration and automation tools are typically required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for interpreting data and coordinating responses. These skills are crucial for quickly detecting, investigating, and mitigating security threats to protect organizational assets.

What are some common challenges faced by professionals working with Microsoft Sentinel SIEM, and how can they be addressed?

Professionals working with Microsoft Sentinel SIEM often encounter challenges such as keeping up with evolving security threats, managing a high volume of alerts, and customizing detection rules to fit their organization's needs. Addressing these issues typically involves ongoing tuning of analytic rules, leveraging automation features like playbooks to reduce manual workload, and regularly collaborating with IT and security teams to ensure that the SIEM is aligned with current business risks. Continuous training and staying updated with Microsoft's documentation and community forums can also help professionals effectively manage and optimize Sentinel deployments.

What is the difference between Sentinel Siem vs Splunk Security Analyst?

AspectSentinel SiemSplunk Security Analyst
CertificationsMicrosoft Certified: Security, Compliance, and Identity Fundamentals, Azure Security EngineerSplunk Certified User, Splunk Core Certified Power User
Work EnvironmentCloud-based SIEM platform, integrated with Azure servicesOn-premises or cloud, data analysis and security monitoring
Industry UsagePrimarily used in organizations leveraging Microsoft Azure and cloud securityUsed across various industries for security data analysis and monitoring

Sentinel Siem focuses on cloud-native security monitoring within Microsoft Azure environments, while Splunk Security Analyst specializes in analyzing security data across diverse platforms. Both roles require knowledge of security principles and data analysis, but Sentinel Siem emphasizes Azure integration, whereas Splunk offers broader data handling capabilities.

What are popular job titles related to Sentinel Siem jobs in Georgia?

For Sentinel Siem jobs in Georgia, the most frequently searched job titles are:

What job categories do people searching Sentinel Siem jobs in Georgia look for?

The top searched job categories for Sentinel Siem jobs in Georgia are:

What cities in Georgia are hiring for Sentinel Siem jobs?

Cities in Georgia with the most Sentinel Siem job openings:

Microsoft Sentinel Subject Matter Expert

2T Consulting

Mableton, GA โ€ข On-site

Full-time

Posted 11 days ago


Job description

We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement, optimize, and manage Microsoft Sentinel and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection, incident response, security automation, cloud security, and compliance across enterprise Azure environments.

Roles and Responsibilities
  • Design, implement, configure, and manage Microsoft Sentinel SIEM/SOAR solutions.
  • Integrate security data sources into Azure Log Analytics, including Syslog, CEF, APIs, and threat intelligence feeds.
  • Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards.
  • Develop automated security response workflows using Azure Logic Apps and Microsoft Copilot for Security.
  • Perform threat hunting, incident investigation, detection engineering, and response activities in collaboration with SOC teams.
  • Implement and manage Azure security controls aligned with Zero Trust principles.
  • Configure and secure enterprise Azure environments, including identity, access, monitoring, and security services.
  • Assess vulnerabilities, analyze attacker TTPs, and support remediation and security improvement initiatives.
  • Integrate and manage Microsoft Defender XDR, including Defender for Endpoint, Office 365, Identity, and Cloud Apps.
  • Support cloud security governance, compliance, risk assessments, and audit activities.
  • Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and cloud security initiatives.
  • Develop security standards, operational procedures, and best practices for Sentinel and Azure security services.
  • Collaborate with Security Operations, Cloud Engineering, Identity, Application Security, and Governance teams.
Required Qualifications
  • Bachelorโ€™s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • 5+ years of cybersecurity experience, including strong hands-on experience with Microsoft Sentinel engineering and administration.
  • Strong expertise in:
    • Microsoft Sentinel
    • Azure Log Analytics
    • Kusto Query Language (KQL)
    • Azure Logic Apps
    • Microsoft Defender XDR
    • Azure Security and Identity Services
    • Microsoft Entra ID
    • Privileged Identity Management (PIM)
    • Conditional Access
    • Security monitoring and incident response
    • CI/CD security and application security scanning
  • Strong understanding of SIEM/SOAR, threat detection, threat hunting, incident response, and security automation.
  • Experience implementing security controls in enterprise Azure environments.
  • Strong knowledge of Zero Trust architecture and cloud security best practices.
Preferred Qualifications
  • Experience with Azure Government / Government Cloud environments.
  • Experience with FISMA, FedRAMP, and NIST security and compliance frameworks.
  • Relevant certifications such as CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Cybersecurity Architect Expert.
  • Experience working with security auditors, compliance teams, and executive stakeholders.