Get more replies from employers
Send a job-specific resume in minutes.
Tekskills seeks a talented Cyber Security Architect with 10–12 years of hands-on experience to lead EDR and SIEM operations. The role covers Defender and SentinelOne, MS Sentinel workflow, and diverse WAF platforms.
You will tune IDS/IPS rules, build KQL-based detections, and develop playbooks to enhance security posture. Candidates should understand Linux, Windows, AD, and network logging; readiness for US shift timing; and optional certifications SC-200/SC-100/CCNA Security/AZ-500 will be an
Should have minimum 10 - 12 years of experience in the following technologies and tools including MS Defender, MS Sentinel, MS Intune, MS Purview, SentinelOne, Cisco IDS/IPS, Checkpoint IDS/IPS, F5 DCS WAF.
Experience in implementing, maintaining, and optimizing MS Purview DLP solutions will be good to have.
Should have knowledge in Kusto query language; playbook & workbook creation and updation, logic app configuration in MS Sentinel.
Understanding of Linux, Windows, AD, Network, and security event logging.
In-depth understanding of security threats, threat attack methods and the current threat environment to develop detection use cases.
Ensure effective operation of SIEM content: filters, rules, expressions and other identification mechanisms of the threat and vulnerability management technologies.
Provide professional data analysis to drive further security measures and risk mitigation activities.
Strong verbal and written interpersonal communication skills.
Willingness to work in US shift timings as required to support the team or at priority calls.
Completion of one or more certifications on the below is an added advantage: SC-200, SC-100, CCNA Security, AZ-500.