Bucharest, ROM
1 day ago
Security Consultant
**Introduction** The Sentinel Content Engineer is responsible for designing, implementing, tuning, and maintaining Microsoft Sentinel content to enable effective detection, response, and automation within the Client Security Operations Center (CSOC). This role ensures that Sentinel provides high-fidelity detections, automated response capabilities, and actionable dashboards aligned with the threat landscape and client requirements. The engineer works closely with SOC analysts (L1/L2), threat intelligence teams, and client stakeholders to develop and continuously improve security use cases, analytics rules, and playbooks. **Your role and responsibilities** Security Consultant - Intelligence & Operations **Required technical and professional expertise** • Microsoft Sentinel Expertise • Strong hands-on experience with Microsoft Sentinel (SIEM + SOAR). • Proficiency in KQL (Kusto Query Language) for writing and optimizing queries. • Experience with Logic Apps for playbook creation and orchestration. • Familiarity with Microsoft security stack (Defender, EOP, Azure Security Center). • Detection & Response Engineering • Ability to translate threat intelligence and MITRE ATT&CK techniques into detection logic. • Experience tuning detections to balance coverage and noise reduction. • Knowledge of incident response workflows and SOC operations. • Automation & Scripting • Proficiency with PowerShell, Python, or other scripting languages for automation. • Experience with API integrations (REST, Graph API). • Log Management & Data Analysis • Understanding of common log sources (Windows Event Logs, network devices, cloud services). • Experience with log normalization, parsing, and schema mapping (ASIM). • Soft Skills & Behavioral Competencies • Strong problem-solving and analytical mindset. • Ability to communicate complex technical concepts to analysts and stakeholders. • Proactive in identifying improvements and proposing new detection/automation content. • High attention to detail with commitment to documentation and knowledge sharing. **Preferred technical and professional experience** • Bachelor’s degree in Cybersecurity, Computer Science, or equivalent experience. • 3-5 years of experience in SOC, SIEM engineering, or security content development. • Microsoft Security certifications preferred: o SC-200 (Microsoft Security Operations Analyst) o SC-100 (Microsoft Cybersecurity Architect) o AZ-500 (Azure Security Engineer Associate) • Other security certifications a plus (GCIA, GCTI, Splunk Certified, etc.). IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Confirmar seu email: Enviar Email
Todos os Empregos de IBM