L2 Security Engineer (Implementation – Microsoft Sentinel & Defender Suite)

Xencia Technology Solutions

Bengaluru

On-site

INR 1,400,000 - 2,300,000

Full time

10 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Xencia Technology Solutions is seeking an L2 Security Implementation Engineer to deliver Microsoft Sentinel and Defender Suite deployments. The role focuses on implementation, onboarding, integration, policy configuration, and customer delivery, not SOC monitoring.

The candidate should bring 4+ years of hands-on experience with the Defender XDR suite, Sentinel, and related Azure services, and be comfortable working from office in Bangalore with standard business hours.

Qualifications

  • 4+ years hands-on experience deploying and configuring Microsoft Sentinel and Defender suites.
  • Experience with onboarding data sources, connectors, and policy configuration.
  • Experience with automation rules, SOAR Playbooks (Logic Apps).
  • Strong customer-facing and documentation skills.

Responsibilities

  • Deploy and configure Log Analytics Workspace and data retention.
  • Onboard data sources using connectors across Azure, M365, Defender, and on‑prem.
  • Configure Log Analytics Agents on Windows, Linux, and network appliances.
  • Implement workbooks, dashboards, and basic analytic rules as part of initial setup.
  • Configure and test automation rules & SOAR playbooks to meet customer use cases.
  • Integrate Sentinel with Defender XDR, Azure AD/Entra logs, and on‑prem servers.

Skills

Microsoft Sentinel
Defender for Endpoint
Defender for Identity
Defender for Office 365
Defender for Cloud Apps
Defender for Cloud (Azure)
Azure Log Analytics
KQL
Azure Logic Apps
Azure AD / Entra ID
PowerShell
Linux scripting
Onboarding methods

Tools

Intune
Group Policy

Job description

Microsoft Defender Suite – Deployment & Configuration
Job Description – L2 Security Engineer (Implementation – Microsoft Sentinel & Defender Suite)
Role: L2 Security Implementation Engineer
Experience: 4+ Years required
Specialization: Microsoft Sentinel, Microsoft Defender XDR Suite
Job Type: Full‑Time, 9AM - 7PM from Office in Bangalore (Implementation / Delivery)
Job Summary

We are looking for a skilled L2 Implementation Engineer with 4–5 years of hands‑on experience deploying and configuring Microsoft Sentinel and Microsoft Defender products.

This role focuses entirely on implementation, onboarding, integrations, policy configuration, customer deployments, and technical project delivery—not SOC monitoring.

Key Responsibilities (Implementation‑Focused)
Microsoft Sentinel – Implementation
  • Deploy and configure Log Analytics Workspace, data retention, workspace architecture.
  • Onboard data sources using connectors (Azure services, M365, Defender, Syslog, CEF agents, firewalls, proxies, SaaS apps).
  • Configure Log Analytics Agents / AMA on Windows, Linux, and network appliances.
  • Implement workbooks, dashboards, and basic analytic rules as part of initial setup.
  • Configure and test automation rules & SOAR Playbooks (Logic Apps) to meet customer use cases.
  • Integrate Sentinel with:
    • Microsoft Defender XDR
    • Azure AD / Entra ID logs
    • Azure Activity Logs
    • On‑prem servers
    • Firewalls (Palo Alto, Fortinet, Checkpoint)
Microsoft Defender Suite – Deployment & Configuration
Defender for Endpoint (MDE)
  • Onboard Windows, macOS, Linux devices using onboarding scripts, Intune, Group Policy.
  • Configure AV, EDR, ASR rules, firewall, network protection, web filtering, and device control.
  • Build and deploy endpoint security baselines using Intune or GPO.
Defender for Identity (MDI)
  • Deploy sensors on Domain Controllers.
  • Configure directory services integration.
  • Validate lateral movement and identity monitoring.
Defender for Cloud Apps (MDA/M365D Apps)
  • Configure app connectors (O365, AWS, GCP, Salesforce, ServiceNow).
  • Deploy session control, app discovery, conditional access app control.
  • Enable policies for DLP, file governance, and compliance.
Defender for Office 365
  • Configure Safe Links, Safe Attachments, anti‑phishing policies, impersonation protection.
  • Integrate O365 signals with Sentinel.
Defender for Cloud (Azure Security Center)
  • Configure subscriptions, security policies, recommendations & workload protections.
  • Enable defender plans for VMs, storage, SQL, containers, key vault, etc.
Additional Responsibilities
  • Gather customer requirements and convert them into technical implementation steps.
  • Prepare HLD/LLD documentation, architecture diagrams, implementation plans.
  • Perform POCs, pilots, environment assessments, and configuration validation.
  • Troubleshoot onboarding issues, connector failures, integration errors.
  • Conduct knowledge transfer (KT) sessions to customers post‑deployment.
  • Work with Microsoft Intune for onboarding Defender & deploying policies (if required).
  • Good Power shell and Linux scripting skills
Required Skills
  • Strong experience implementing:
    • Microsoft Sentinel
    • Defender for Endpoint
    • Defender for Identity
    • Defender for Office 365
    • Defender for Cloud Apps
    • Defender for Cloud (Azure)
  • Good hands‑on knowledge of:
    • Azure Log Analytics
    • KQL (basic‑intermediate for validation)
    • Azure Logic Apps (SOAR playbooks)
    • Azure AD / Entra ID logs
  • Strong understanding of onboarding methods, connectors, log ingestion, and device integrations.
Preferred Qualifications
  • Microsoft Certifications:
    • SC‑200 (Security Operations Analyst) / SC‑300 / AZ‑500 / AZ-900
  • Experience with firewalls, proxies, server logs, API integrations (for Sentinel connectors).
Soft Skills
  • Strong communication and customer‑facing skills.
  • Ability to work with delivery teams, architects, and customers.
  • Good documentation skills (HLD/LLD, runbooks).
  • Problem‑solving skills and ownership mindset.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst - L2
Security Analyst - L2

Noventiq Egypt • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Security Analyst - L2
Security Analyst - L2

Noventiq India, Ltd. • Bengaluru

On-site
INR 1,500,000 - 2,200,000
Technical Lead Engineer – Security Delivery
Technical Lead Engineer – Security Delivery

Whitefield Careers • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Microsoft Defender Engineer
Microsoft Defender Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 1,200,000 - 2,200,000
Azure Sentinel
Azure Sentinel

Cloudxtreme • Hyderabad, Chennai District, Bengaluru

On-site
INR 4,500,000 - 6,500,000
Sentinel Solution Architect
Sentinel Solution Architect

Quadrasystems.net • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Career progression acceleration
Innovation culture
Certification sponsorship
+1
Azure Cloud Native Security Engineer(Microsoft Defender Sentinel)
Azure Cloud Native Security Engineer(Microsoft Defender Sentinel)

Alike Thoughts • Bengaluru, Mumbai

On-site
INR 1,200,000 - 1,800,000
Security Architect — Microsoft Security Platform
Security Architect — Microsoft Security Platform

Avanade • Bengaluru

On-site
INR 4,200,000 - 6,000,000
Cyber Security Analyst
Cyber Security Analyst

Genpact • Dadri, Hyderabad, Bangalore Rural

On-site
INR 900,000 - 1,500,000
Cyber Security Engineer
Cyber Security Engineer

Futurism Technologies, INC. • Pune District

On-site
INR 2,500,000 - 3,500,000