Microsoft Sentinel Engineer
Role Description:
We are seeking an experienced Microsoft Sentinel Engineer to join the Cyber Defense Center (CDC) and support the development, optimization, and operation of our Microsoft Sentinel platform.
The successful candidate will be responsible for designing and implementing security monitoring capabilities, onboarding and managing security telemetry, developing detection use cases, and driving security automation initiatives. The role requires strong technical expertise in Microsoft Sentinel, Kusto Query Language (KQL), log management, and security orchestration, as well as the ability to collaborate effectively across security and IT teams.
Key Responsibilities:
- Design, implement, and maintain Microsoft Sentinel security monitoring capabilities.
- Onboard, normalize, and optimize security log sources from cloud and on-premises platforms.
- Develop and maintain analytics rules, detection logic, watchlists, workbooks, and hunting queries.
- Design and implement security automation and orchestration workflows using Logic Apps and Sentinel playbooks.
- Perform log source onboarding, data quality validation, and telemetry coverage assessments.
- Develop and optimize KQL queries for threat detection, investigation, reporting, and threat hunting.
- Collaborate with Security Operations analysts to improve detection coverage and reduce false positives.
- Support threat hunting and incident investigation activities through telemetry analysis and content development.
- Contribute to the continuous improvement of CDC monitoring, detection, and response capabilities.
- Maintain technical documentation, engineering standards, and operational procedures related to Microsoft Sentinel.
Required Education and Experience:
- Minimum 5 years of experience in cybersecurity, with a strong focus on security operations, detection engineering, or SIEM engineering.
- Strong experience onboarding and managing log sources within SIEM platforms.
- Strong experience developing security detections and analytics content.
- Experience designing and implementing security automation workflows.
- Experience working with Microsoft security technologies and Microsoft Defender XDR are considered an advantage.
- Relevant Microsoft certifications are highly desirable (e.g., SC-200, AZ-500).
Required Skills:
- Fluent English speaking and writing
- Ability to collaborate cross-functionally with IT experts throughout the organization.
- Positive mindset, curiosity, open-mindedness, and a proactive approach to problem-solving.
- Excellent team player with strong interpersonal skills and a collaborative mindset.
Starting Date: 1st of September
End Date: Indefinite term (30-day notice period)
Working Hours: 40 hours/week
Location: Europe
Colleagues
Göteborg
Why should you work with us?
-
Flexibility
We are flexible in our processes and adapt to our customers' and suppliers' needs. -
Development
We are one of the fastest growing IT consultant brokers in the Nordic region. -
Perfect match
We match your skills and competencies to the right assignment.
Become an IT- or management consultant
EPICO enables opportunities for you those of you who prefer to be freelance consultants and strive for challenging projects and assignments.
About Epico
EPICO has consultants in several areas ranging from support to infrastructure, development and heavy projects as well as program managers. We adapt to your requirements.
EPICO is a part of the group EPICO A/S.
For more information please visit: http://www.epicogroup.com