HamburgerMenu
hirist

Lead Microsoft Security Engineer - SIEM/Microsoft Sentinel

Terralogic Software Solutions Private Limited.
7 - 10 Years
Bangalore

Posted on: 18/05/2026

Job Description

Lead Microsoft Security Engineer (XDR/AI/SOAR)


Role Summary :


We are looking for a visionary Lead Security Engineer to architect, manage, and evolve our security posture within the Microsoft 100% cloud-native stack. As the technical lead, you will bridge the gap between reactive threat hunting and proactive AI driven defense. You aren't just watching the "blinkenlights" you are building the automated engines that respond to threats before they become headlines.


Key Responsibilities :


1. SIEM & Detection Engineering (Microsoft Sentinel) :


- Architect & Optimize : Design and maintain the Sentinel workspace, ensuring cost efficient log ingestion and optimized data retention.


- KQL Mastery : Write, tune, and maintain complex Kusto Query Language (KQL) queries for advanced hunting and detection rules.


- Threat Hunting : Lead proactive hunting exercises using Sentinel Workbooks and Notebooks to identify stealthy adversaries.


2. Unified XDR Management (Microsoft Defender) :


- Full Stack Integration : Oversee the end to end configuration of the Defender suite (Defender for Endpoint, Identity, Office 365, and Cloud Apps).


- Incident Response : Act as the Tier 3 escalation point for high-severity incidents, leading the investigation from initial alert to remediation.


- Posture Management : Utilize Defender for Cloud to drive secure scores and enforce compliance guardrails across multi cloud environments.


3. AI-Driven Defense (Copilot for Security) :


- Prompt Engineering : Design and refine custom "Promptbooks" and security specific agents to accelerate incident summarization and triage.


- AI Integration : Leverage Copilot to reverse engineer malicious scripts and translate complex telemetry into natural language for executive stakeholders.


- Capacity Planning : Stay ahead of the curve by implementing the latest Copilot plugins and integrating them into standard SOC workflows.


4. Automation & SOAR (Azure Logic Apps) :


- Workflow Automation : Build and maintain sophisticated Logic App playbooks to automate repetitive tasks (e.g., auto isolating compromised devices, disabling at risk accounts).


- API Integration : Connect Sentinel and Defender to external ITSM tools (like ServiceNow) and third party APIs to create a unified response ecosystem.


Technical Qualifications :


- Experience : 7+ years in Cybersecurity, with at least 3 years specifically leading teams in a Microsoft centric environment.


- Tooling : Expert level proficiency in Microsoft Sentinel, Microsoft Defender XDR, and Azure Logic Apps.


- AI/ML : Hands-on experience with Microsoft Copilot for Security (or early adopter proficiency in Generative AI for SecOps).


- Coding : Strong proficiency in KQL and PowerShell; experience with Python or REST APIs is a significant plus.


Preferred Certifications :


- SC-100 : Microsoft Cybersecurity Architect


- SC-200 : Microsoft Security Operations Analyst


- AZ-500 : Microsoft Azure Security Engineer Associate

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...