採用
Job Description
The Sentinel Platform Engineer – L3 is the highest-tier technical expert responsible for end-to-end engineering, optimization, and advanced troubleshooting of the Microsoft Sentinel platform within the SOC. This role ensures platform reliability, architecture governance, seamless data ingestion, analytics development, automation, threat detection maturity, and integration with enterprise security controls.
The L3 engineer also acts as the primary escalation point for complex incidents and provides guidance to L1/L2 SOC teams.
͏
Key Responsibilities
1.
Sentinel Platform Ownership & Architecture:
-
Own full lifecycle management of Microsoft Sentinel, including architecture design, scaling, performance optimization, and maintenance.
-
Define and enforce Sentinel platform governance, naming standards, and RBAC policies.
-
Design and enhance Log Analytics workspace architecture, data retention policies, and workspace linking.
-
Ensure high availability, cost optimization, and platform resilience.
2.
Data Connectors & Ingestion Engineering:
-
Onboard, configure, and troubleshoot Sentinel data connectors (Syslog, CEF, AMA, custom connectors, API integrations).
-
Build and manage scalable data ingestion pipelines for security logs from telco, cloud, network, and core systems.
-
Optimize ingestion costs, data normalization (ASIM), and data mapping.
3.
Analytics Rules & Threat Detection Engineering:
-
Develop and optimize KQL-based analytic rules for advanced threat detection.
-
Improve detection logic through threat hunting patterns, MITRE ATT&CK mapping, and false-positive reduction.
-
Perform periodic health checks on analytics rule performance and data coverage.
4. SOAR, Automation & Playbook Engineering
-
Build advanced Logic Apps and SOAR playbooks for automated response.
-
Integrate automation across security tools, ITSM, identity systems, and network controls.
-
Troubleshoot complex automation failures and enhance playbook efficiencies.
5.
Advanced Troubleshooting & Escalation Support:
-
Serve as final technical escalation point for Sentinel platform issues.
-
Analyze and resolve ingest failures, connector breakdowns, workspace anomalies, and rule malfunctions.
-
Support IR teams with deep-dive KQL investigations and platform-level forensics.
6. Monitoring, Health, and Performance Management
-
Continuously monitor Sentinel health, connector stability, ingestion latency, and automation performance.
-
Conduct regular platform audits and enforce configuration compliance.
-
Maintain dashboards for platform KPIs and operational maturity.
7. Documentation, Standards, and Best Practices
-
Create and maintain engineering runbooks, platform architecture diagrams, and standard operating procedures.
-
Mentor L1/L2 SOC analysts and provide technical knowledge sessions.
-
Participate in change management, risk assessments, and security architecture reviews.
͏
Required Skills & Experience
Technical Skills
-
Expert-level hands-on experience with Microsoft Sentinel (minimum 4–6 years).
-
Strong proficiency in KQL, including performance tuning and complex query building.
Deep understanding of:
-
Log Analytics Workspaces
-
Azure Monitor Agent (AMA)
-
Sentinel Analytics, Workbooks, Watchlists
-
Logic Apps / SOAR automation
-
REST API integration
-
ASIM & Schema Mapping
-
Knowledge of security frameworks: MITRE ATT&CK, NIST CSF, ISO 27001.
-
Experience with Windows, Linux, network logs, firewalls, proxies, identity systems (AD/AAD).
-
Strong debugging skills in ingestion issues, schema mismatches, parsing/normalization.
総閲覧数
0
応募クリック数
0
模擬応募者数
0
スクラップ
0
類似の求人
Wiproについて

Wipro
PublicA technology services and consulting company focused on building solutions that address clients' digital transformation needs.
10,001+
従業員数
Bengaluru
本社所在地
$8.5B
企業価値
レビュー
3.1
10件のレビュー
ワークライフバランス
3.5
報酬
2.3
企業文化
3.8
キャリア
2.5
経営陣
2.2
45%
友人に勧める
良い点
Good training and learning opportunities
Flexible work hours and remote options
Supportive colleagues and teamwork
改善点
Low and uncompetitive compensation
Limited growth and career advancement opportunities
Poor management direction and support
給与レンジ
41,395件のデータ
Mid/L4
Mid/L4 · Analyst - Business Process L2
1件のレポート
$128,283
年収総額
基本給
$111,550
ストック
-
ボーナス
-
$128,283
$128,283
面接体験
5件の面接
難易度
2.0
/ 5
期間
14-28週間
内定率
40%
体験
ポジティブ 100%
普通 0%
ネガティブ 0%
面接プロセス
1
Application Review
2
Online Assessment/Aptitude Test
3
Technical Interview
4
HR Interview
5
Offer
よくある質問
Coding/Algorithm
Technical Knowledge
Behavioral/STAR
Past Experience
Culture Fit
ニュース&話題
Wipro share buyback, target prices: What Jefferies, Morgan Stanley, others say after soft Q1 guidance - MSN
MSN
News
·
3d ago
Wipro attrition falls to 13.8%, headcount inches up by 136 - The Economic Times
The Economic Times
News
·
4d ago
Wipro shares slide up to 4% after weak Q4, muted outlook dents sentiment - The Times of India
The Times of India
News
·
4d ago
Indian shares rise on peace deal hopes; Wipro, HDFC Life cap gains - TradingView — Track All Markets
TradingView — Track All Markets
News
·
4d ago



