Security Engineer ll – Microsoft Sentinel SIEM

Posted 5 Days Ago
Be an Early Applicant
Bengaluru, Karnataka, IND
Hybrid
Mid level
Security • Cybersecurity
The Role
Administer and optimize Microsoft Sentinel and Defender XDR environments across managed client tenants. Responsibilities include onboarding log sources, engineering KQL detections, mapping use cases to MITRE ATT&CK, investigating Tier 2 alerts, developing Azure Logic Apps SOAR automation, monitoring ingestion and connector health, and creating operational documentation and standards.
Summary Generated by Built In
We Help the World Be Everyday Ready™

Today's threatscape is relentless. So are we. At Cyderes, we build practical Identity & Access Management (IAM), Exposure Management, and risk programs, helping organizations stop active threats fast with Managed Detection & Response (MDR) that integrates with existing tools. Powering it all is Meridian, our entity fabric that connects identities, assets, and access into one trusted reality. Augmented by AI and driven by seasoned operators, our tireless global team arms organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way.

🏆 Great Place to Work® Certified™ | United States | Canada | United Kingdom | India

About the Job

The Security Engineer ll – Microsoft Sentinel & Defender XDR plays a critical engineering role within Cyderes' Managed Sentinel SIEM and MDR services.

You will go beyond basic platform administration. The Security Engineer ll is responsible for detection engineering, platform optimization, onboarding lifecycle execution, and Defender XDR integration. You will be a trusted technical resource to clients, ensuring you configure, improve, and improve their Microsoft security ecosystem against evolving threats.

You will represent and promote the Cyderes brand through collaboration, and delivery that meets client expectations.

You will report to Senior Manager, Managed Platforms.

Responsibilities:

  • Administer and maintain Microsoft Sentinel and Defender XDR environments across multiple managed client tenants, ensuring platform health and availability.
  • Support platform intake and provide coverage during Eastern Time business hours, including troubleshooting of platform and telemetry issues.
  • Onboard and integrate new log sources and security data into Sentinel, validating connectivity, parsing, normalisation, data quality, and entity mapping.
  • Maintain, and tune Sentinel detection rules using KQL, including Scheduled, NRT, and Fusion analytics, with a focus on reducing false positives and improving alert fidelity.
  • Map detection use cases to MITRE ATT&CK and contribute to reusable detection, threat-hunting, dashboards, workbooks, and reporting libraries.
  • Monitor Sentinel and Defender XDR alerts and perform Tier 2 investigation and escalation support for MDR/SOC teams.
  • Develop SOAR automation using Azure Logic Apps, including automated response actions such as device isolation, user disablement, IP blocking, and ticket creation.
  • Monitor ingestion volumes, connector health, and data quality while identifying opportunities for platform standardisation, performance improvement, and cost optimization across the MSSP environment.
  • Develop runbooks, SOPs, onboarding documentation, and detection standards while staying current with Microsoft security platform capabilities and industry best practices.

Requirements

  • Diploma or Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience.
  • 3–5 years of experience in cybersecurity, SOC, security engineering, or related roles, with at least 2 years of hands-on Microsoft Sentinel experience.
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Azure Log Analytics, and KQL.
  • Experience working in an MSSP, MDR, or customer-facing security environment with multi-tenant Azure environments; Azure Lighthouse experience.
  • Experience with Windows and Linux logs, Entra ID, networking fundamentals, authentication/authorization, and common security telemetry.
  • Experience with Azure Logic Apps, REST APIs, and scripting using PowerShell or Python.
  • Working knowledge of the MITRE ATT&CK framework and MDR/SOC operational workflows.
  • We prefer relevant certifications such as SC-200, AZ-500, SC-100, Security+, or Microsoft Defender certifications.
  • Documentation, with the ability to balance daily platform operations, detection engineering, and continuous improvement.



WHY CYDERES? 

Benefits that go beyond the basics, we support our people so they can do their best work.

✔ Medical Insurance - Employee + dependents covered

✔ Life Insurance - Protection for what matters most

✔ Retirement Match Program - We invest in your future

✔ Hybrid Work Model - 2–3 days in office

✔ Maternity & Paternity Leave - Time for the moments that matter

✔ Paid Time Off - PTO + sick & casual leave

✔ Bereavement & Volunteer Time - Give back to your community

✔ Professional Development - Reimbursement program

✔ LinkedIn L&D Platform - Thousands of courses at your fingertips

✔ Mobile Phone Reimbursement - Stay connected, on us

 
Cyderes is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to race, religion, color, sex, age, disability, sexual orientation, genetic information, national origin, or veteran status.
 
Note: This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.
 
 

Skills Required

  • Diploma or bachelor's degree in Computer Science, Cybersecurity, Information Technology, a related field, or equivalent practical experience
  • 3-5 years of experience in cybersecurity, SOC, security engineering, or related roles
  • At least 2 years of hands-on Microsoft Sentinel experience
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Azure Log Analytics, and KQL
  • Experience working in an MSSP, MDR, or customer-facing security environment
  • Experience with multi-tenant Azure environments and Azure Lighthouse
  • Experience with Windows and Linux logs, Entra ID, networking fundamentals, authentication and authorization, and common security telemetry
  • Experience with Azure Logic Apps, REST APIs, and scripting using PowerShell or Python
  • Working knowledge of the MITRE ATT&CK framework and MDR/SOC operational workflows
  • Relevant certifications such as SC-200, AZ-500, SC-100, Security+, or Microsoft Defender certifications
  • Strong documentation skills and ability to balance platform operations, detection engineering, and continuous improvement
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Kansas City, MO
882 Employees
Year Founded: 2020

What We Do

Cyderes is a global cybersecurity partner built for today’s relentless threatscape. We specialize in identity-centric security, managed detection and response, and cloud defense—powered by AI and driven by expert operators. Our mission: arm organizations with the people, platforms, and perspective to "be everyday ready.”

Similar Jobs

Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
289097 Employees

The Aerospace Corporation Logo The Aerospace Corporation

Advanced Cyber Sec Archt/Engr

Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4600 Employees
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
4109 Employees

JumpCloud Logo JumpCloud

Support Engineer

Cloud • Information Technology • Security • Software
Easy Apply
In-Office or Remote
Bangalore, Bengaluru, Karnataka, IND
800 Employees

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account