Sentinel Sr Analyst
Short Description
Required Skills & Experience
- 6 to 8 years of cybersecurity experience, preferably with exposure to the Middle East market.
- 4+ years of hands-on experience with Microsoft Sentinel in enterprise or MSSP environments.
- Strong expertise in Microsoft Azure security services and architecture.
- Proven experience managing large-scale SIEM deployments and SOC operations.
- Advanced knowledge of Azure Logic Apps and security automation.
- Strong understanding of hybrid security architectures, cloud networking, and log management.
- Experience with MITRE ATT&CK-based detection engineering.
- Excellent analytical, reporting, and dashboarding skills.
Preferred Competencies
- Strong ownership, accountability, and problem-solving skills.
- Excellent communication and stakeholder management abilities.
- Ability to simplify complex technical concepts for business audiences.
- Experience working within SOC L1/L2/L3 operating models and major incident management processes.
SIEM & Security Operations
- Lead the architecture, implementation, and management of large-scale Microsoft Sentinel environments.
- Support complex hybrid architectures across multi-cloud, on-premises, multi-tenant, and multi-subscription environments.
- Ensure SIEM platform health, log ingestion, connector performance, and overall operational excellence.
- Drive SOC maturity through detection tuning, dashboard optimization, and automation initiatives.
- Lead major incident investigations, root cause analysis, and escalation management.
- Act as the primary escalation point for L1/L2 analysts and support BAU SOC operations.
- Manage ITSM ticket lifecycle and ensure adherence to SLA metrics (TTD, TTR, MTTR).
- Contribute to governance, reporting, and security review activities.
Security Engineering & Detection
- Provide advanced expertise in Microsoft Azure security architecture and integrations.
- Onboard and integrate log sources from Windows/Linux endpoints, network devices, security appliances, and SaaS platforms.
- Design and optimize MITRE ATT&CK-aligned detection use cases and analytics rules.
- Leverage Microsoft Defender XDR technologies to enhance threat detection and response capabilities.
- Develop operational dashboards and executive-level security reports.
Automation & Integrations
- Design and implement SOAR playbooks using Azure Logic Apps.
- Integrate Microsoft Sentinel with ITSM platforms, Threat Intelligence feeds, TIP solutions, and Vulnerability Management tools.
- Troubleshoot cloud, network, and data flow issues impacting security monitoring.
Documentation & Stakeholder Management
- Create high-quality HLDs, LLDs, architecture diagrams, and operational documentation.
- Present security findings, recommendations, and reports to technical and executive stakeholders.
- Act as a trusted advisor, translating technical risks into business-relevant insights.
Dubai, AE