Sentinel Engineer (Fully remote, Westcoast Hours)

SkyeBiz

United States

Remote

USD 135,000 - 155,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

SkyeBiz in the United States is seeking a skilled Sentinel Engineer to join our cybersecurity team. The role spans log sources integration, data connectors deployment, and tuning ingestion and detection engineering with KQL analytics, hunting queries, and MITRE ATT&CK mappings.

You will lead log integration on onboarding projects, drive technical engagement, configure audit settings, deploy Function Apps, and optimize costs while collaborating with client teams and Azure DevOps pipelines.

Qualifications

  • Minimum 2 years hands-on Sentinel design and implementation experience.
  • Minimum 5 years total cybersecurity experience (engineering, operations or detection).
  • Strong proficiency in KQL (Kusto Query Language).
  • Hands-on Linux system administration experience.
  • Solid networking fundamentals.
  • Experience deploying and managing Azure Arc and AMA, including DCRs.
  • Experience with syslog collection architectures and Windows event collection.
  • Experience operating in multi-tenant Azure environments.
  • Strong knowledge of Microsoft Entra ID and Active Directory logging.
  • Experience with Microsoft Defender XDR and Sentinel–Defender integration.
  • Familiarity with Sentinel content surface (Content Hub, analytics rules, workbooks, watchlists, threat intel connectors).
  • Proficiency in PowerShell/Python scripting.
  • Experience with Git workflows and IaC.
  • Excellent problem-solving and communication abilities.

Responsibilities

  • Act as the technical lead for log integration on client onboarding projects—owning the engineering end-to-end.
  • Drive scoping, sequencing and tracking of log integration workstreams; engage client infrastructure when needed.
  • Research, test and advise on audit configuration settings for log sources to ensure proper logs for detection.
  • Deploy data connectors and troubleshoot ingestion; customize Function Apps as required.
  • Prototype integrations for new log sources and create repeatable template configurations for clients.
  • Validate parsers, fix and enhance, and optimise log collection for cost efficiency.
  • Develop and maintain Sentinel analytics rules, hunting queries and workbooks.
  • Engage with client cybersecurity professionals on detection strategy and use-case prioritisation.

Skills

KQL
Linux
Networking
PowerShell/Python
Git workflows
Threat detection
MITRE ATT&CK
Detection engineering
Communication
Multi-client management

Tools

Azure DevOps
REST APIs
Cribl Stream
SIEM tools

Job description

USA | $135k to $155k per annum | Permanent
Reports To: Head: SIEM Engineering
On-Call: Participation in a major-incident on-call rotation. Activations are infrequent, typically 3 or 4 times a year, and are reserved for significant security incidents requiring engineering support outside normal hours.
Job Summary

Our client is looking for a skilled and experienced Sentinel Engineer to join our cybersecurity team. The role covers both sides of the Sentinel platform: integrating log sources, deploying and enhancing data connectors, developing custom connectors where required, and optimising ingestion, and detection engineering, writing and tuning KQL analytics rules, building hunting queries, and translating threat-actor TTPs into detections that catch real attacks with low false-positive rates.

Responsibilities
Primary
  • Act as the technical lead for log integration on client onboarding projects --- owning the engineering end-to-end, working alongside a project manager who runs the overall programme.
  • Scope log integration workstreams, sequence the work, and track technical progress through delivery. Where there is no project manager in the loop --- for example, a new log-source type being driven directly with the client --- drive the technical engagement yourself, including pushing client infrastructure teams to open firewall rules, fix GPOs and unblock dependencies.
  • Research, test and advise clients on audit configuration settings for log sources, to ensure that the right logs flow into Sentinel for threat detection.
  • Deploy data connectors and troubleshoot data ingestion, including deployment of Function Apps, customisation and enhancement of Function App code where required, and development of custom log ingestion solutions.
  • Research and prototype integrations for unfamiliar log sources --- working from vendor documentation, standing up lab instances, generating representative events, validating the end-to-end path into Sentinel, and producing a repeatable template configuration for client deployment.
  • Validate log parsing, fix and enhance existing parsers, and develop new parsers.
  • Optimise collected logs so the right events are captured and unnecessary events are filtered out, managing consumption and cost.
  • Develop and maintain Sentinel analytics rules --- scheduled queries, NRT rules, and Fusion/anomaly rules --- mapped to MITRE ATT&CK techniques.
  • Build and maintain hunting queries and workbooks to support proactive threat hunting and investigations.
  • Engage with client cybersecurity professionals on detection strategy, requirements gathering and use-case prioritisation.
  • Translate threat intelligence and threat-actor TTPs into deployable detections, including detection-as-code workflows for review, testing and rollout.
Secondary
  • Use the team's Azure DevOps repos and pipelines day-to-day --- committing code, raising pull requests, and contributing to pipeline content that scales services across multiple clients.
  • Sentinel health checks and periodic maintenance, e.g., data connector updates.
  • Tune existing analytics rules for false-positive reduction, and integrate applicable changes from upstream rule repositories into the rule base.
  • Document solution design and develop technical processes and procedures to enhance the knowledge base and aid standardisation efforts.
  • Analyse security logs across the full breadth of client environments to inform parser development and detection authoring.
Qualifications and Experience
Mandatory
  • Minimum of 2 years hands-on Sentinel design and implementation experience.
  • Minimum of 5 years total cybersecurity experience (engineering, operations or detection --- not consulting or advisory).
  • Strong proficiency in KQL (Kusto Query Language).
  • Hands-on Linux system administration experience.
  • Solid networking fundamentals.
  • Experience deploying and managing Azure Arc and AMA, including DCRs.
  • Experience with syslog collection architectures and Windows event collection.
  • Experience operating in multi-tenant Azure environments.
  • Working knowledge of Microsoft Entra ID and Active Directory logging.
  • Solid experience working with security logs across multiple domains and product types.
  • Experience with Microsoft Defender XDR and Sentinel--Defender integration.
  • Familiarity with Sentinel content surface (Content Hub, analytics rules, workbooks, watchlists, threat intelligence connectors).
  • Strong understanding of the threat landscape and MITRE ATT&CK.
  • Demonstrable detection-engineering experience.
  • Proficiency in PowerShell/Python scripting.
  • Comfortable with Git workflows and infrastructure-as-code.
  • Experience with detection-as-code workflows.
  • Excellent problem-solving skills and communication abilities.
  • Ability to manage multiple concurrent client engagements.
Nice to Have
  • Familiarity with ASIM.
  • Experience with Codeless Connector Framework (CCF).
  • Experience integrating with REST APIs.
  • Experience setting up/administering Azure DevOps.
  • Microsoft certifications (SC-200, AZ-104, AZ-500, SC-100).
  • Hands-on incident response experience.
  • Familiarity with Sigma rules.
  • Penetration testing background.
  • Experience with Cribl Stream.
Personal Qualities
  • Deeply knowledgeable and hands-on.
  • Trusted to own work end-to-end.
  • Go-getter mindset with initiative.
  • Thorough and proactive.
  • Client-ready and confident.
  • Strong prioritiser in multi-project environments.
  • Quality-focused, avoids quick fixes.
  • Willing to put in discretionary effort when needed.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. SIEM Engineering Consultant
Sr. SIEM Engineering Consultant

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 180,000
Software Developer - Microsoft Sentinel
Software Developer - Microsoft Sentinel

Cyberobotix • Austin (TX)

On-site
USD 90,000 - 120,000
Competitive salary
Flexible work environment
Sentinel Engineer
Sentinel Engineer

Arctiq: Intelligent Architecture • Brentwood (TN)

On-site
USD 110,000 - 170,000
Microsoft Sentinel Security Platform Engineer
Microsoft Sentinel Security Platform Engineer

Allied Consultants, Inc. • Austin (TX)

On-site
USD 120,000 - 190,000
Highly competitive pay rates
Medical insurance
401(k) plan with company match
+1
Azure Engineer (Sentinel)
Azure Engineer (Sentinel)

Primo Talents Inc • Sentinel (OK)

On-site
USD 83,000 - 138,000
Sr. Azure cloud engineer
Sr. Azure cloud engineer

Radiant Digital • Austin (TX)

On-site
USD 90,000 - 120,000
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 120,000 - 190,000
Sentinel Engineer
Sentinel Engineer

Arctiq • Brentwood (TN)

On-site
USD 120,000 - 170,000
Sr. DFIR Analyst
Sr. DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
Sr. Threat Hunter
Sr. Threat Hunter

SentinelOne • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Home office allowance
+1