This role is a hands-on Azure Sentinel expert responsible for leading a greenfield Sentinel build and expansion within an Azure cloud environment. Sentinel is already deployed, but this individual will drive the core buildout, integration, and operational maturity of the platform.
They will function as the technical driver—not a project manager—and are expected to come in with strong, real-world Sentinel expertise.
REQUIRED SKILLS
- Expert-level proficiency in Microsoft Sentinel
- Operating in a FedRAMP environment
- Design and implement - Analytics rules and detections
- Log parsing and normalization
EDUCATIONAL/SKILL/EXPERIENCE REQUIREMENTS
Education/Experience
· Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field
· Equivalent combination of education and related experience
· 5 years of experience in a Security Operations Center (SOC), Incident Response, Azure Cloud Security
Required Skills and Knowledge
· Extensive SOC experience (L3/Senior/Principal level), serving as an escalation point for complex and high-severity incidents
· Expert-level proficiency in Microsoft Sentinel (Azure SIEM), with deep expertise in log ingestion, integration, data lifecycle management, and incident investigation.
· Strong expertise in log normalization, parsing, and data quality management, ensuring high-fidelity detections
· Demonstrated ability to optimize SIEM performance, reducing noise while improving detection accuracy and coverage
· Experience with automation and orchestration, including Sentinel playbooks and Logic Apps to enhance response efficiency
· Deep experience in detection engineering, including designing, implementing, and tuning analytics aligned to MITRE ATT&CK
· Advanced KQL expertise for large-scale data analysis, threat hunting, and detection development
· Expertise in managing and utilizing a wide range of security tools, including Next Generation Firewall, IDS/IPS, EDR, AV, MS Defender Suite, Internet Proxy, other Cloud Security Tools, etc.
· Strong knowledge of cloud and enterprise security technologies, including Microsoft Defender suite, identity security (Entra ID), EDR/XDR, firewalls, and cloud-native controls
· Proven leadership in threat hunting and incident response, including RCA and continuous improvement of detection and response capabilities
· Strong communication and stakeholder engagement skills, with the ability to influence technical and non-technical teams
· Demonstrated mentorship of SOC analysts, driving operational maturity
· Relevant certifications (SC-200, AZ-500, CySA+) preferred
· Strong analytical and problem-solving skills, with the ability to operate effectively in a fast-paced environment
· Commitment to continuous learning and staying current with evolving threats and technologies