Security Engineer

🔥 12 hours ago

🇺🇦 Ukraine – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Integrity360

Integrity360

201 - 500 employees

💼 Consulting

🏥 Healthcare

🛡️ Insurance

Consulting • Healthcare • Insurance

Integrity360 is a leading independent cyber security and PCI specialist in Europe, providing dedicated experts for managed services, consulting services, penetration testing, and incident response. The company focuses on a security-first philosophy, helping organizations prepare for cyber threats by enhancing their resilience across networks, infrastructure, and information. Integrity360 operates five Security Operations Centres across Europe and South Africa, delivering 24/7 protection against cyber attacks. Services offered include managed detection and response, incident response, cyber testing, compliance maintenance, and more, ensuring security breaches are quickly identified and resolved. Recognized by Gartner, Integrity360 continues to expand globally and invest in its cutting-edge security operations facilities.

📋 Description

• Deliver end-to-end onboarding of client Microsoft Sentinel environments into the MSSP service • Configure Sentinel workspaces, content solutions, data connectors, analytics rules, automation rules, watchlists and workbooks • Run technical discovery sessions covering log sources, connectivity, data volumes, retention, dependencies and priorities • Onboard Microsoft, third-party, cloud, network, identity and application log sources using Azure Monitor Agent, Data Collection Rules, APIs, syslog, CEF and custom connectors • Design and implement data filtering and transformation to improve signal quality and control ingestion costs • Validate ingestion, parsing, field mapping, timestamps, health and coverage; troubleshoot source, collector, network and Azure issues • Tune analytics rules, alert logic and incident generation with SOC and detection engineering teams • Onboard and integrate Microsoft Defender XDR workloads, including Defender for Endpoint, Defender for Identity, Defender for Office 365 and Defender for Cloud Apps • Produce high-level designs, implementation plans, configuration records, test evidence, operational runbooks and handover documentation • Coordinate with clients, project managers, architects, SOC analysts and service teams on dependencies, risks, actions and service transition readiness • Apply engineering standards, peer review and change control; improve onboarding templates, technical patterns and internal procedures • Support troubleshooting and remediation during onboarding and early-life support • Undertake occasional travel where required for client delivery • Manage assigned onboarding activities from discovery and design through implementation, testing, documentation and handover • Report to the Head of Cloud Security & Microsoft Security Services

🎯 Requirements

• Hands-on experience deploying, configuring or supporting Microsoft Sentinel in production or customer environments • Practical knowledge of Sentinel data connectors, Log Analytics workspaces, Azure Monitor Agent, Data Collection Rules, syslog and CEF collection patterns • Strong Kusto Query Language skills • Experience onboarding and troubleshooting log sources across Microsoft 365, Azure, endpoints, identity, network, security and third-party platforms • Understanding of ingestion filtering, data transformation, parsing, normalisation, retention and security telemetry costs • Experience creating technical designs and delivery documentation, including HLDs, implementation plans, test records and operational handover materials • Working knowledge of Microsoft Defender XDR and integration with Microsoft Sentinel • Understanding of SIEM operations, detection engineering, incident workflows and managed security service requirements • Strong troubleshooting skills across Azure, APIs, identity, networking and data collection components • Confident written and verbal communication skills with technical and non-technical client stakeholders • Ability to manage assigned work independently while collaborating with project, architecture, SOC and service teams • Experience working for an MSSP, MDR provider, Security Operations Centre or security-focused professional services team is desired • Experience with custom log parsers, KQL functions, ASIM-compatible content or normalisation patterns is desired • Experience with DevOps pipelines, source control, detection as code, infrastructure as code and automation is desired • Knowledge of Microsoft Sentinel repositories, content management and multi-customer deployment patterns is desired • Experience integrating Microsoft security services across tenants, subscriptions or delegated administration models is desired • Familiarity with MITRE ATT&CK is desired • Microsoft Certified: Security Operations Analyst Associate (SC-200) is desired • Microsoft Certified: Azure Security Engineer Associate (AZ-500/SC-500) is desired • Microsoft Certified: Cybersecurity Architect Expert (SC-100) is desired • Relevant Microsoft Applied Skills or other relevant security/cloud certifications are beneficial but not essential

🏖️ Benefits

• Learning, development and progression opportunities • Training and certification opportunities across Microsoft security technologies • Support from an experienced team

Apply Now

Similar Jobs

🕒 September 17

Plug and Play Tech Center

501 - 1000

💼 Consulting

🏥 Healthcare

✈️ Travel

Cloud Security Engineer securing Playtech’s Azure and GCP environments. Improving cloud governance, controls, monitoring, and incident response for a global gaming technology company.

AWS

Azure

Cloud

Firewalls

Google Cloud Platform

Linux

Python

TCP/IP

🕒 August 21

MWDN

51 - 200

💼 Consulting

📦 Logistics

🏥 Healthcare

Security Researcher investigating browser, mobile, and attacker techniques for IAM software. Developing fraud-detection signals and SDK requirements for global enterprise users.

Android

Cyber Security

iOS

Java

JavaScript

Kotlin

Objective-C

Python

Swift

TypeScript

🕒 August 21

Plug and Play Tech Center

501 - 1000

💼 Consulting

🏥 Healthcare

✈️ Travel

Cloud Security Engineer securing Azure and GCP environments for Playtech’s regulated gaming technology. Maintaining CSPM controls, auditing cloud security, and automating threat response.

AWS

Azure

Cloud

Firewalls

Google Cloud Platform

Linux

Python

TCP/IP

🕒 July 28

Plug and Play Tech Center

501 - 1000

💼 Consulting

🏥 Healthcare

✈️ Travel

Cloud Security Engineer ensuring the security of cloud environments at Playtech. Collaborating with product teams to maintain secure operations on Azure or GCP.

Azure

Cloud

Google Cloud Platform

Linux

Python

TCP/IP