We are seeking a highly skilled Azure Sentinel Specialist to join our cybersecurity team. The ideal candidate will be responsible for managing and optimizing Azure Sentinel, conducting threat detection and response, and integrating security solutions. This role requires strong expertise in Azure Sentinel and experience with various security technologies.
Role & responsibilities
Monitoring of SIEM and other security solutions dashboards, as assigned.
Handling incidents escalated by the L1/L2 team in 24x7 rotational shifts.
Carry out in-depth investigation and correlation and work with the stakeholders towards mitigation and closure of critical, high severity and other complex incidents.
SIEM support activities which includes adhoc reporting and basic troubleshooting.
Coordinating with Security SMEs to build hunting rules and triggers, which focus on adversary activity within the ICS/OT domain.
Minimize gaps in incident response and provide for comprehensive risk mitigation.
Updating of incident response playbooks to cater for emerging threat scenarios and ensure response actions align with the best practices.
Prepare reports, KPI dashboard for customers.
Liaise with stakeholders in relation to cyber security issues and provide future recommendations.
Assist with the creation, maintenance and delivery of cyber security awareness training for colleagues.
Hands-on experience in network security technologies Such as SIEM (Azure Sentinel), Next Gen Firewalls, Proxy, IDS / IPS, DDOS, Antimalware protection, DNS Security, VPN Security, Cloud Firewalls (E.g., NSG).
Working Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g; application of defense-in-depth).
Should have working experience in Cloud platforms such as AWS or Azure or GCP.
Handle multiple competing priorities and high impact incidents/escalations.
Share learnings and best practices amongst team members including keeping internal knowledge databases updated.
SOC Team Shift Roster Management & Keep Security Operation Centre running 24x7.
Preferred candidate profile:
Preferred Skills:
Keyskills: Sentinel Azure Sentinel SOC SIEM