Azure Sentinel Architect
ICT Division |
Perm |
0178203040 |
£65000 - £75000 per annum + Good Pension offering, Car, Health |
North West |
MZP128056 |
27-11-2024 03:32 PM |
Job Summary:
We are seeking a talented Azure Sentinel Architect with 2-5 years of experience to design, implement, and optimize our customers Azure Sentinel-based Security Information and Event Management (SIEM) systems. As an Azure Sentinel Architect, you will be responsible for developing a comprehensive security strategy, defining architecture and policies, integrating and optimizing threat detection, and enabling advanced security monitoring to ensure our customer's digital assets remain secure from cyber threats.
You'll work collaboratively with cybersecurity engineers and analysts, IT teams, and other stakeholders to assess security needs of our clients, configure Sentinel to address them, and continuously adapt our systems to emerging threats.
This is a hybrid role which depending on the engagement may require travel to client locations.
Key Responsibilities:
* Design and Implementation
o Lead the design and implementation of Azure Sentinel to build a robust security monitoring and alerting system.
o Architect an Azure Sentinel solution to enhance security posture through real-time threat detection, investigation, and response.
o Design custom dashboards, workbooks, and automated workflows to streamline security monitoring.
* Configuration and Optimization
o Configure and fine-tune Azure Sentinel rules, connectors, and playbooks to optimize threat detection and response capabilities.
o Ensure scalability and performance by optimizing Sentinel resources, data connectors, and data ingestion pipelines.
o Develop policies and procedures to ensure Azure Sentinel configuration aligns with industry best practices and compliance standards.
* Security Analysis and Threat Detection
o Collaborate with security analysts to implement effective use cases and threat hunting scenarios within Azure Sentinel.
o Develop and manage custom queries using KQL (Kusto Query Language) to identify potential security incidents and perform forensic analysis.
o Set up, manage, and refine automated incident response playbooks for efficient response to threats and alerts.
* Integrations and Automations
o Integrate Azure Sentinel with other security tools and platforms, such as Microsoft Defender, Entra ID, and third-party security systems.
o Implement SOAR (Security Orchestration, Automation, and Response) functionalities to enhance incident response times.
o Ensure seamless integration with IT infrastructure and continuous monitoring across cloud, hybrid, and on-premises environments.
* Documentation and Training
o Develop comprehensive documentation for Azure Sentinel designs, configurations, playbooks, and workflows.
o Provide training and guidance to security team members on Azure Sentinel's use and capabilities.
o Ensure the knowledge transfer and documentation of procedures for incident response, monitoring, and alert management.
* Continuous Improvement
o Regularly review and refine security policies, incident response playbooks, and Sentinel configurations based on the latest threat landscape.
o Stay current with Azure Sentinel updates, new connectors, and best practices for cybersecurity and compliance.
o Collaborate with IT teams to improve monitoring coverage and overall security posture.
Required Skills and Experience:
* Experience:
o Minimum 5 years of experience in cybersecurity, with at least 2 years focused on Azure Sentinel and/or Microsoft Azure Security.
o Strong experience in SIEM design, implementation, and administration.
o Strong problem-solving skills and analytical mindset with the ability to work under pressure.
o Excellent communication skills to collaborate with both technical and non-technical stakeholders.
* Technical Skills:
o Proficiency in Kusto Query Language (KQL) for Sentinel query writing.
LA International is a HMG approved ICT Recruitment and Project Solutions Consultancy, operating globally from the largest single site in the UK as an IT Consultancy or as an Employment Business & Agency depending upon the precise nature of the work, for security cleared jobs or non-clearance vacancies, LA International welcome applications from all sections of the community and from people with diverse experience and backgrounds.
Award Winning LA International, winner of the Recruiter Awards for Excellence, Best IT Recruitment Company, Best Public Sector Recruitment Company and overall Gold Award winner, has now secured the most prestigious business award that any business can receive, The Queens Award for Enterprise: International Trade, for the second consecutive period.
We are seeking a talented Azure Sentinel Architect with 2-5 years of experience to design, implement, and optimize our customers Azure Sentinel-based Security Information and Event Management (SIEM) systems. As an Azure Sentinel Architect, you will be responsible for developing a comprehensive security strategy, defining architecture and policies, integrating and optimizing threat detection, and enabling advanced security monitoring to ensure our customer's digital assets remain secure from cyber threats.
You'll work collaboratively with cybersecurity engineers and analysts, IT teams, and other stakeholders to assess security needs of our clients, configure Sentinel to address them, and continuously adapt our systems to emerging threats.
This is a hybrid role which depending on the engagement may require travel to client locations.
Key Responsibilities:
* Design and Implementation
o Lead the design and implementation of Azure Sentinel to build a robust security monitoring and alerting system.
o Architect an Azure Sentinel solution to enhance security posture through real-time threat detection, investigation, and response.
o Design custom dashboards, workbooks, and automated workflows to streamline security monitoring.
* Configuration and Optimization
o Configure and fine-tune Azure Sentinel rules, connectors, and playbooks to optimize threat detection and response capabilities.
o Ensure scalability and performance by optimizing Sentinel resources, data connectors, and data ingestion pipelines.
o Develop policies and procedures to ensure Azure Sentinel configuration aligns with industry best practices and compliance standards.
* Security Analysis and Threat Detection
o Collaborate with security analysts to implement effective use cases and threat hunting scenarios within Azure Sentinel.
o Develop and manage custom queries using KQL (Kusto Query Language) to identify potential security incidents and perform forensic analysis.
o Set up, manage, and refine automated incident response playbooks for efficient response to threats and alerts.
* Integrations and Automations
o Integrate Azure Sentinel with other security tools and platforms, such as Microsoft Defender, Entra ID, and third-party security systems.
o Implement SOAR (Security Orchestration, Automation, and Response) functionalities to enhance incident response times.
o Ensure seamless integration with IT infrastructure and continuous monitoring across cloud, hybrid, and on-premises environments.
* Documentation and Training
o Develop comprehensive documentation for Azure Sentinel designs, configurations, playbooks, and workflows.
o Provide training and guidance to security team members on Azure Sentinel's use and capabilities.
o Ensure the knowledge transfer and documentation of procedures for incident response, monitoring, and alert management.
* Continuous Improvement
o Regularly review and refine security policies, incident response playbooks, and Sentinel configurations based on the latest threat landscape.
o Stay current with Azure Sentinel updates, new connectors, and best practices for cybersecurity and compliance.
o Collaborate with IT teams to improve monitoring coverage and overall security posture.
Required Skills and Experience:
* Experience:
o Minimum 5 years of experience in cybersecurity, with at least 2 years focused on Azure Sentinel and/or Microsoft Azure Security.
o Strong experience in SIEM design, implementation, and administration.
o Strong problem-solving skills and analytical mindset with the ability to work under pressure.
o Excellent communication skills to collaborate with both technical and non-technical stakeholders.
* Technical Skills:
o Proficiency in Kusto Query Language (KQL) for Sentinel query writing.
LA International is a HMG approved ICT Recruitment and Project Solutions Consultancy, operating globally from the largest single site in the UK as an IT Consultancy or as an Employment Business & Agency depending upon the precise nature of the work, for security cleared jobs or non-clearance vacancies, LA International welcome applications from all sections of the community and from people with diverse experience and backgrounds.
Award Winning LA International, winner of the Recruiter Awards for Excellence, Best IT Recruitment Company, Best Public Sector Recruitment Company and overall Gold Award winner, has now secured the most prestigious business award that any business can receive, The Queens Award for Enterprise: International Trade, for the second consecutive period.