Security Infrastructure Engineer - Sentinel
MEEZA QSTP · Doha
Job description
About the role
The Security Infrastructure Engineer – Sentinel will design, build, and maintain the data ingestion and automation pipelines that feed Microsoft Sentinel and Sentinel SOAR. You will work closely with cloud architects, SOC analysts, and infrastructure teams to ensure high‑quality telemetry is available for detection and response.
Key responsibilities
- Architect and operate multi‑cloud telemetry ingestion (GCP, AWS, Azure) using Bind Plane Forwarders, Cloud‑to‑Cloud connectors and Webhooks.
- Develop and troubleshoot custom parsers (CBN) to normalize non‑standard logs into the Unified Data Model (UDM).
- Build dashboards to monitor ingestion rates, latency and data drops.
- Design, code and maintain automated incident‑response playbooks in Sentinel SOAR using Python and visual builders.
- Create and manage API integrations between Sentinel SOAR and third‑party tools (firewalls, EDR, IAM, ticketing systems).
- Automate repetitive SOC tasks such as artifact enrichment, evidence gathering and initial containment.
- Configure case‑management settings, custom fields, stages and SLA tracking.
- Monitor platform health, manage RBAC and ingest threat‑intel feeds (Mandiant, VirusTotal).
- Collaborate with Tier 1/2 analysts to tune YARA‑L rules and translate manual workflows into playbooks.
- Partner with cloud architects and IT teams to configure logging, Pub/Sub and deploy Bind Plane Forwarders on‑premises.
Required profile
- Bachelor’s degree in Computer Science, IT, Cybersecurity or equivalent.
- 3–5 years of hands‑on experience with SIEM platforms, preferably Azure Sentinel.
- Relevant certifications such as Azure Sentinel certification; security certifications (Security+, CySA+, CEH, CISSP, GCIH) are a plus.
Required skills
- Python programming
- Azure Sentinel and Sentinel SOAR
- Bind Plane Forwarders
- GCP, AWS and Azure cloud services
- Cloud‑to‑Cloud connectors, Webhooks, API integration
- Unified Data Model (UDM) and custom parser development
- YARA‑L rule authoring
- RBAC management
- Threat‑intel feed integration (Mandiant, VirusTotal)
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Qatar.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 4 weeks ago
Expires 1 month from now
27 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
MEEZA QSTP
Doha