5 months ago
Hyderābād, IndiaSenior
Responsibilities
- Own Microsoft Sentinel configuration and day-to-day operations.
- Onboard and maintain Microsoft and third-party log sources and data connectors while ensuring data quality, normalization, and cost efficiency.
- Develop and maintain automation rules, Logic Apps playbooks, and workflows to improve SOC efficiency and response consistency.
- Support incidents, outages, and performance issues affecting the Sentinel platform.
- Own Microsoft Purview configuration and day-to-day operations.
- Implement and tune sensitivity labels, DLP policies, and data-classification rules according to business and regulatory requirements.
- Oversee deployment, maintenance, upgrades, health monitoring, and lifecycle management for assigned security tools.
- Collaborate with security architects and cross-functional stakeholders to evaluate and select security tools.
- Create and maintain security configuration documentation and standard operating procedures.
- Monitor emerging data-security threats and research SIEM tools, techniques, and leading practices.
Requirements
- At least 5 years of work experience in cybersecurity.
- Bachelor’s degree or equivalent experience preferred.
- Production enterprise experience administering Microsoft Sentinel or a similar SIEM tool.
- Production enterprise experience administering Microsoft Purview or a similar data-security tool.
- Proficiency in scripting and programming languages such as Python or PowerShell for automation and orchestration.
- Experience with KQL or other query languages and analytic rules.
- Familiarity with Microsoft XDR, including MDE, MDI, MDO, and MDCA, or similar security tools.
- Strong analytical, problem-solving, troubleshooting, communication, and cross-functional collaboration skills.
- Knowledge of enterprise technologies including databases, operating systems, and web applications.
- Practical knowledge of risk treatment, exception management, compensating controls, and risk tolerance.
- Knowledge of disaster recovery and computer forensic tools, technologies, and methods.
- Relevant certifications such as CISSP, CISA, or CISM are highly desirable.
Benefits
- 100% in-office work arrangement.
- Minimal travel required.
- Reasonable accommodation is available for applicants with disabilities.
- TriNet is an equal opportunity employer.