Job Title: Cyber Security Consultant - Sentinel SIEM Engineer
Department: Security
Location: [Dubai]
Job Summary
We are seeking a highly skilled and experienced Sentinel SIEM Engineer to join our growing security team. You will be responsible for the implementation, configuration, and ongoing management of our Sentinel SIEM platform. You will play a critical role in protecting our organization from cyber threats by leveraging Sentinel to detect, investigate, and respond to security incidents.
Responsibilities
- Design, implement, and configure Sentinel SIEM for efficient log ingestion, normalization, and analysis.
- Develop and maintain comprehensive security rules and detections for threat identification.
- Investigate security incidents using Sentinel SIEM, including data analysis, correlation, and root cause analysis.
- Generate security reports and dashboards to provide insights into security posture and trends.
- Collaborate with security analysts and other IT teams to improve security posture and incident response procedures.
- Stay up-to-date on the latest Sentinel SIEM features and security threats.
- Participate in security testing and vulnerability assessments.
- Automate security workflows and incident response processes using Sentinel automation capabilities.
Qualifications
- Minimum 3+ years of experience in security operations with a focus on SIEM technologies.
- Proven experience with Microsoft Sentinel SIEM, including deployment, configuration, and log management.
- Strong understanding of security information and event management (SIEM) concepts and principles.
- Experience with security incident and event management (SIEM) rule development and tuning.
- Experience with security analytics tools and techniques, including Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), and Endpoint Detection and Response(EDR).
- Experience with Kusto Query Language (KQL) for querying data in Sentinel.
- Excellent understanding of network security concepts, including firewalls, intrusion detection/prevention systems (IDS/IPS), and network traffic analysis.
- Experience with threat intelligence feeds and integration with SIEM.
- Excellent analytical and problem-solving skills.
- Strong communication and collaboration skills.
- Ability to work independently and as part of a team.
- A passion for cybersecurity and staying current with the latest threats and vulnerabilities.
Preferred Qualifications
- Experience with Microsoft Azure cloud technologies.
- Experience with scripting languages such as Python or PowerShell for automating SIEM tasks.
- Security certifications such as Security+, CISSP, or GSEC.
Benefits
- Competitive salary and benefits package.
- Opportunity to work on challenging and impactful projects.
- Work with a talented and experienced security team.
- Be part of a growing and innovative company.
Skills: security,siem,sentinel,management,automation,cyber,incident response,microsoft