Tech Stack
AzureCloudVault
About the role
- Design and optimize enterprise-scale Sentinel SIEM/analytics solutions
- Architect and manage ADX clusters for scalable, cost-optimized query and hunting workloads
- Build and tune Cribl pipelines (Edge & Stream) for telemetry routing, enrichment, and normalization
- Integrate across the Azure stack (Logic Apps, Event Hub, Functions, Key Vault, etc.) for automation and resilience
- Design and engineer ingestion pipelines from multiple log sources into Sentinel/ADX
- Develop and optimize KQL queries, detection rules, dashboards, and workbooks
- Ensure telemetry pipelines are reliable, scalable, and compliant with enterprise logging standards
- Drive performance benchmarking and cost governance for large-scale data ingestion
- Act as a technical SME and advisor for cross-functional security and infrastructure teams
- Mentor and support Specialist-level engineers to uplift team skills in Sentinel, ADX, and Cribl
- Partner with incident response, threat hunting, and cloud engineering teams to translate requirements into scalable solutions
Requirements
- 6–10+ years of IT/security engineering experience
- 3–5+ years focused on Microsoft Sentinel & Azure security stack
- Proven expertise in ADX schema design, query optimization, and capacity planning
- Hands-on experience with Cribl (Stream, Edge) for enterprise-scale log routing and transformation
- Strong proficiency in KQL, Azure Logic Apps, and data ingestion pipelines
- Deep understanding of SIEM architectures, SOAR automation, and cloud-native security controls
- Flexible Work Arrangements: Hybrid
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Sentinel SIEMADXCriblKQLdata ingestion pipelinesquery optimizationcapacity planningtelemetry routingdetection rulesdashboards
Soft skills
mentoringtechnical SMEcross-functional collaborationperformance benchmarkingcost governance