Sentinel Engineer: Threat Detection & Ingestion Lead

SkyeBiz

United States

Remote

USD 135,000 - 155,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

SkyeBiz in the United States is seeking a skilled Sentinel Engineer to join our cybersecurity team. The role spans log sources integration, data connectors deployment, and tuning ingestion and detection engineering with KQL analytics, hunting queries, and MITRE ATT&CK mappings.

You will lead log integration on onboarding projects, drive technical engagement, configure audit settings, deploy Function Apps, and optimize costs while collaborating with client teams and Azure DevOps pipelines.

Qualifications

  • Minimum 2 years hands-on Sentinel design and implementation experience.
  • Minimum 5 years total cybersecurity experience (engineering, operations or detection).
  • Strong proficiency in KQL (Kusto Query Language).
  • Hands-on Linux system administration experience.
  • Solid networking fundamentals.
  • Experience deploying and managing Azure Arc and AMA, including DCRs.
  • Experience with syslog collection architectures and Windows event collection.
  • Experience operating in multi-tenant Azure environments.
  • Strong knowledge of Microsoft Entra ID and Active Directory logging.
  • Experience with Microsoft Defender XDR and Sentinel–Defender integration.
  • Familiarity with Sentinel content surface (Content Hub, analytics rules, workbooks, watchlists, threat intel connectors).
  • Proficiency in PowerShell/Python scripting.
  • Experience with Git workflows and IaC.
  • Excellent problem-solving and communication abilities.

Responsibilities

  • Act as the technical lead for log integration on client onboarding projects—owning the engineering end-to-end.
  • Drive scoping, sequencing and tracking of log integration workstreams; engage client infrastructure when needed.
  • Research, test and advise on audit configuration settings for log sources to ensure proper logs for detection.
  • Deploy data connectors and troubleshoot ingestion; customize Function Apps as required.
  • Prototype integrations for new log sources and create repeatable template configurations for clients.
  • Validate parsers, fix and enhance, and optimise log collection for cost efficiency.
  • Develop and maintain Sentinel analytics rules, hunting queries and workbooks.
  • Engage with client cybersecurity professionals on detection strategy and use-case prioritisation.

Skills

KQL
Linux
Networking
PowerShell/Python
Git workflows
Threat detection
MITRE ATT&CK
Detection engineering
Communication
Multi-client management

Tools

Azure DevOps
REST APIs
Cribl Stream
SIEM tools

Job description

SkyeBiz in the United States is seeking a skilled Sentinel Engineer to join our cybersecurity team. The role spans log sources integration, data connectors deployment, and tuning ingestion and detection engineering with KQL analytics, hunting queries, and MITRE ATT&CK mappings.

You will lead log integration on onboarding projects, drive technical engagement, configure audit settings, deploy Function Apps, and optimize costs while collaborating with client teams and Azure DevOps pipelines.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sentinel Engineer (Fully remote, Westcoast Hours)
Sentinel Engineer (Fully remote, Westcoast Hours)

SkyeBiz • United States

Remote
USD 135,000 - 155,000
Azure Engineer (Sentinel)
Azure Engineer (Sentinel)

Primo Talents Inc • Sentinel (OK)

On-site
USD 83,000 - 138,000
Remote Sentinel Detection Content Engineer
Remote Sentinel Detection Content Engineer

BlueVoyant • United States

Remote
USD 99,000 - 132,000
Sentinel Security Engineer: SIEM & SOAR Expert
Sentinel Security Engineer: SIEM & SOAR Expert

Arctiq: Intelligent Architecture • Brentwood (TN)

On-site
USD 110,000 - 170,000
Sr. SIEM Engineering Consultant
Sr. SIEM Engineering Consultant

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 180,000
Remote Security Content Engineer: Detection & Automation
Remote Security Content Engineer: Detection & Automation

BlueVoyant • United States

Remote
USD 101,000 - 149,000
Remote Senior SIEM Engineer — Microsoft Sentinel Expert
Remote Senior SIEM Engineer — Microsoft Sentinel Expert

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 180,000
Senior Microsoft Sentinel Engineer: Security Automation
Senior Microsoft Sentinel Engineer: Security Automation

Arctiq • Brentwood (TN)

On-site
USD 120,000 - 170,000
Sr. Azure cloud engineer
Sr. Azure cloud engineer

Radiant Digital • Austin (TX)

On-site
USD 90,000 - 120,000
Senior Security Engineer: Azure Sentinel & AI Security
Senior Security Engineer: Azure Sentinel & AI Security

Coherent Corp. • San Francisco (CA)

Hybrid
USD 180,000 - 240,000