Get more replies from employers
Send a job-specific resume in minutes.
1 week ago Be among the first 25 applicants
Get AI-powered advice on this job and more exclusive features.
Direct message the job poster from NextByt Innovations
Job Title
Assistant Manager – Sentinel Administration
DepartmentInformation Security Group (ISG)
Direct SupervisorVP – Head of Cyber Defense Center
Job Number Job PurposeAdministration:
The Microsoft Sentinel Administrator is responsible for managing and maintaining Microsoft Sentinel, a cloud-native SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation, and Response) solution. This role involves configuring data connectors, creating and tuning analytics rules, managing workbooks and dashboards, and automating incident response workflows. The administrator ensures continuous monitoring, threat detection, and incident response across the organization’s IT environment, while collaborating with security teams to enhance threat visibility and response capabilities.
DimensionsNumber of Staff
1
Others
India
Key Result Areas·Ensure continuous monitoring of security events across integrated systems, Develop and maintain analytics rules to detect suspicious activities and reduce false positives and improve detection accuracy
·Connect and manage data sources (e.g., Azure, Microsoft 365, on-premises systems), Optimize data ingestion and retention policies and ensure data normalization and enrichment for effective analysis.
·Design and maintain workbooks and dashboards for real-time visibility, generate periodic reports on security posture and incident trends and provide actionable insights to stakeholders
·Create and manage playbooks using Azure Logic Apps and automate repetitive tasks and incident response workflows and reduce mean time to detect (MTTD) and mean time to respond (MTTR).
·Monitor Sentinel performance and health, apply updates, patches, and configuration changes as needed and ensure high availability and scalability of the Sentinel environment
·Maintain documentation for configurations, rules, and procedures, support compliance audits by providing necessary logs and reports and align Sentinel operations with organizational security policies
·Work closely with SOC teams, IT, and other stakeholders, provide training and support for Sentinel users and participate in incident investigations and post-mortems.
Key Principles
·Prioritize proactive threat detection and response, Ensure confidentiality, integrity, and availability of data.
·Leverage automation (e.g., playbooks, Logic Apps) to streamline incident response, reduce manual effort and improve response times.
·Regularly refine detection rules and analytics based on evolving threats, Stay updated with Microsoft Sentinel updates and best practices.
·Provide clear, actionable insights through dashboards and reports, ensure stakeholders have visibility into the security posture.
·Seamlessly integrate with diverse data sources (cloud, on-prem, hybrid), Design solutions that scale with organizational growth.
·Maintain thorough documentation of configurations, rules, and processes, Support compliance with industry standards and regulatory requirements.
· Work closely with SOC teams, IT, and business units, Communicate effectively during incidents and investigations.
Operating Environment, Framework and Boundaries, Working Relationships
·HO (Head Office), Local CISOs, Regulators and Supervisors across the bank
·Cyber Security Standards and Industry best practices
·All business units including LOD 1-3 including LOD1 – Business, DPP, Technology, LOD-2 Group Compliance, Fraud Prevention, Risk Management and LOD-3 Internal Audit.
Problem Solving·Analytical Thinking: The ability to break down complex problems into manageable parts and analyze them systematically is crucial for identifying security threats and vulnerabilities.
·Technical Proficiency: Deep understanding of security technologies, protocols, and tools is essential for designing and implementing Sentinel solutions.
·Creativity: Innovative thinking helps in developing unique solutions to security challenges, especially when standard approaches are insufficient.
Decision Making Authority & Responsibility·Sentinel Assistant Manager is a SME role who has overall responsibility for Sentinel processes withing the Security Incident Response domain and supporting the Head of Cyber Defense Center to achieve organization’s Information Security strategy and goals.
·Confirm adequacy of the process controls against Security Incident response policies, standards and applicable regulatory requirements.
Knowledge, Skills, and ExperienceEssential knowledge
·Have over 7+ years of rich experience in information security domain and at least 4-5 years of dedicated experience in Microsoft Sentinel and other SIEM (ArcSight) solutions.
·Hands on experience in implementing and operationalizing tools preferably on Sentinel and ArcSight
·Familiarity with advanced SOC monitoring technologies, risk, threat and security measures.
·Knowledge across the SOC domains including governance, control frameworks, policies, compliance management, risk management and incident response etc.
·Preferably worked in BFSI domain with proven experience in SOC function.
·Knowledge of key security standards and regulations such as NIST 800-61, CERT/CC, PCI, ISO 27035 etc.
Skills and Application
·Ability to configure data connectors, analytics rules, and automation playbooks.
·Skills in PowerShell, Azure Logic Apps, or other automation tools.
·Creating custom workbooks and visualizations for security insights.
·Experience deploying, configuring, and managing Sentinel in a production environment.
·Involvement in real-world incident detection, triage, and response.
·Collaborate with other IS teams, Ops and tech teams on enhancing security incident response resilience
Other
·Sound knowledge of evolving advanced tech stacks and related control and risk universe from a SOC perspective.
·The ideal candidate will have a technical or computer science degree.
·Microsoft Certified: Security Operations Analyst Associate (SC-200)
·Microsoft Certified: Azure Security Engineer Associate (AZ-500)
Referrals increase your chances of interviewing at NextByt Innovations by 2x
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.