Senior SIEM Engineer: Microsoft Sentinel & Cloud Security

ECS Corporate Services

Fairfax (VA)

Remote

USD 140,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Everforth ECS is seeking a Sr. SIEM Engineering Consultant to join our team remotely. You will design, deploy, and optimize Microsoft Sentinel environments at scale, with data ingestion pipelines, detection rules, dashboards, and automation.

You will collaborate with engineering, DevOps, cloud, and client teams to deliver high-performance SIEM capabilities while ensuring security visibility and cost efficiency. US-based travel may be required for on-site engagements.

Qualifications

  • Hands-on expertise with Microsoft Sentinel and Azure Monitor.
  • Experience in SIEM engineering including log ingestion, normalization, detection engineering, and incident response workflows.
  • Proficiency in Kusto Query Language (KQL) for detection development and data analysis.
  • Strong scripting and automation skills (Python, PowerShell, Bash).
  • Solid understanding of security operations, threat detection, and observability in distributed systems.
  • Experience designing, deploying, and optimizing production-scale SIEM environments.
  • Strong knowledge of Azure, cloud security architecture, networking, and identity systems.
  • Ability to mentor, guide, and influence engineering teams on SIEM and security best practices.
  • Outstanding verbal and written communication skills.
  • Willingness to support domestic or international on-site engagements.

Responsibilities

  • Design, deploy, and maintain Microsoft Sentinel environments, including Log Analytics Workspaces and data connectors.
  • Build and optimize data ingestion pipelines, detection rules (analytics), queries (KQL), dashboards (Workbooks), and automation workflows.
  • Write scripts, automation, and integrations (Python, PowerShell, Bash, etc.) to streamline security operations, data processing, and monitoring.
  • Deploy and manage Sentinel across cloud environments, primarily Azure, with integrations into AWS, GCP, and hybrid/on-premises environments.
  • Leverage automation and orchestration tools such as Terraform, Ansible, CI/CD pipelines, and infrastructure-as-code to manage deployments and operational tasks.
  • Integrate Sentinel with enterprise tools such as Microsoft Defender, identity providers, firewalls, EDR platforms, and other telemetry sources.
  • Monitor system health, troubleshoot ingestion and performance issues, and optimize for cost, reliability, and scalability.
  • Develop and tune detection use cases aligned to threat frameworks (e.g., MITRE ATT&CK).
  • Configure incident management, alert grouping, and response workflows within Sentinel.
  • Implement automation and response using playbooks (Logic Apps) for alert enrichment and remediation.
  • Lead design reviews, provide guidance on SIEM best practices, and support knowledge sharing across teams.
  • Maintain documentation for architectures, detection logic, deployment patterns, runbooks, and operational best practices.
  • Stay current with Microsoft security technologies, Sentinel features, and emerging SIEM capabilities.

Skills

Microsoft Sentinel
Azure Monitor
KQL
Python
PowerShell
Bash
Terraform
Ansible
CI/CD
Security operations

Tools

Terraform
Ansible
Logic Apps

Job description

Everforth ECS is seeking a Sr. SIEM Engineering Consultant to join our team remotely. You will design, deploy, and optimize Microsoft Sentinel environments at scale, with data ingestion pipelines, detection rules, dashboards, and automation.

You will collaborate with engineering, DevOps, cloud, and client teams to deliver high-performance SIEM capabilities while ensuring security visibility and cost efficiency. US-based travel may be required for on-site engagements.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. SIEM Engineering Consultant
Sr. SIEM Engineering Consultant

ECS Corporate Services • Fairfax (VA)

Remote
USD 140,000 - 180,000
Senior Security Ops Engineer - Remote, Microsoft Sentinel
Senior Security Ops Engineer - Remote, Microsoft Sentinel

CruiTek, LLC • United States

Remote
USD 140,000 - 180,000
Remote work
Unlimited growth
Senior Cyber Sentinel Architect - Cloud XDR & SIEM
Senior Cyber Sentinel Architect - Cloud XDR & SIEM

Deloitte France • Jacksonville (FL)

On-site
USD 105,000 - 208,000
Security Engineer - Build & Own Microsoft Sentinel SIEM
Security Engineer - Build & Own Microsoft Sentinel SIEM

Saragossa • New Jersey

On-site
USD 180,000 - 220,000
Bonus
Sentinel Security Engineer: SIEM & SOAR Expert
Sentinel Security Engineer: SIEM & SOAR Expert

Arctiq: Intelligent Architecture • Brentwood (TN)

On-site
USD 110,000 - 170,000
Senior Cyber Defense Consultant | Sentinel & Cloud Security
Senior Cyber Defense Consultant | Sentinel & Cloud Security

Deloitte France • Kansas City (MO)

On-site
USD 105,000 - 208,000
Remote Senior Splunk Engineer — Observability & SIEM Lead
Remote Senior Splunk Engineer — Observability & SIEM Lead

ECS Corporate Services • Fairfax (VA)

Remote
USD 140,000 - 190,000
Senior SIEM/EDR Engineer – Managed Services
Senior SIEM/EDR Engineer – Managed Services

Critical-Start- • Washington

On-site
USD 120,000 - 140,000
Competitive salary with bonuspotential
Comprehensive health benefits
Unlimited PTO
+3
Senior Cyber Defense Consultant: Microsoft Sentinel & XDR
Senior Cyber Defense Consultant: Microsoft Sentinel & XDR

Deloitte France • Tallahassee (FL)

On-site
USD 105,000 - 208,000
Senior Microsoft Sentinel Engineer: Security Automation
Senior Microsoft Sentinel Engineer: Security Automation

Arctiq • Brentwood (TN)

On-site
USD 120,000 - 170,000