Security Infrastructure Engineer - Sentinel
MEEZA QSTP · Doha
وصف الوظيفة
About the role
The Security Infrastructure Engineer – Sentinel will design, build, and maintain the data ingestion and automation pipelines that feed Microsoft Sentinel and Sentinel SOAR. You will work closely with cloud architects, SOC analysts, and infrastructure teams to ensure high‑quality telemetry is available for detection and response.
Key responsibilities
- Architect and operate multi‑cloud telemetry ingestion (GCP, AWS, Azure) using Bind Plane Forwarders, Cloud‑to‑Cloud connectors and Webhooks.
- Develop and troubleshoot custom parsers (CBN) to normalize non‑standard logs into the Unified Data Model (UDM).
- Build dashboards to monitor ingestion rates, latency and data drops.
- Design, code and maintain automated incident‑response playbooks in Sentinel SOAR using Python and visual builders.
- Create and manage API integrations between Sentinel SOAR and third‑party tools (firewalls, EDR, IAM, ticketing systems).
- Automate repetitive SOC tasks such as artifact enrichment, evidence gathering and initial containment.
- Configure case‑management settings, custom fields, stages and SLA tracking.
- Monitor platform health, manage RBAC and ingest threat‑intel feeds (Mandiant, VirusTotal).
- Collaborate with Tier 1/2 analysts to tune YARA‑L rules and translate manual workflows into playbooks.
- Partner with cloud architects and IT teams to configure logging, Pub/Sub and deploy Bind Plane Forwarders on‑premises.
Required profile
- Bachelor’s degree in Computer Science, IT, Cybersecurity or equivalent.
- 3–5 years of hands‑on experience with SIEM platforms, preferably Azure Sentinel.
- Relevant certifications such as Azure Sentinel certification; security certifications (Security+, CySA+, CEH, CISSP, GCIH) are a plus.
Required skills
- Python programming
- Azure Sentinel and Sentinel SOAR
- Bind Plane Forwarders
- GCP, AWS and Azure cloud services
- Cloud‑to‑Cloud connectors, Webhooks, API integration
- Unified Data Model (UDM) and custom parser development
- YARA‑L rule authoring
- RBAC management
- Threat‑intel feed integration (Mandiant, VirusTotal)
Questions fréquentes
لماذا تبلغ عن هذا العرض؟
اكتشف المزيد
الرواتب والأدلة وعمليات البحث في قطر.
الرواتب حسب المهنة
قدم طلبك في 30 ثانية
أدخل بريدك الإلكتروني للتقديم. سيتم إنشاء حساب تلقائياً.
بالمتابعة، أنت توافق على شروط الاستخدام.
لديك حساب بالفعل؟ تسجيل الدخول
لديك سؤال حول هذا العرض؟
اطرحه هنا: ستصلك تفاصيل العرض كاملة عبر البريد الإلكتروني، فوراً.
عزز فرصك
حمّل سيرتك الذاتية وسنقترح عليك الوظائف التي تناسب ملفك.
جاري تحليل سيرتك الذاتية...
MEEZA QSTP
Doha