What are the responsibilities and job description for the Azure Sentinel Engineer position at Purview Infotech?
Azure Sentinel Engineer
Location: Charlotte, NC and Iselin, NJ and Dallas, TX- Onsite
-
specializes in designing, implementing, and managing Microsoft Sentinel (formerly Azure Sentinel), a cloud-native SIEM and SOAR solution.
-
Log data connectors, create KQL-based analytics rules, develop automation playbooks (SOAR), and investigate security incidents to protect cloud/hybrid infrastructure.
-
Deep knowledge of SIEM/SOAR functions, workspaces, and analytics rules.
-
Configuring data ingestion from Azure Activity Logs, Microsoft Defender for Cloud, and third-party sources into Log Analytics Workspaces.
-
Developing KQL (Kusto Query Language) queries for analytics rules to detect security threats and creating hunting queries.
-
Building automated workflows (playbooks) for rapid incident response.
-
Analyzing alerts and managing incident lifecycles within the Sentinel dashboard
-
Identifying vulnerabilities and hardening Azure environments