Security Infrastructure Engineer - Sentinel
MEEZA QSTP · Doha
وصف الوظيفة
About the role
The Security Infrastructure Engineer – Sentinel will design, build and maintain the data ingestion pipelines and SOAR automation for a multi‑cloud security operations platform. You will work closely with SOC analysts, cloud architects and infrastructure teams to ensure high‑quality telemetry flows into Azure Sentinel and related tools.
Key responsibilities
- Architect and operate telemetry ingestion from GCP, AWS and Azure using Bind Plane Forwarders, Cloud‑to‑Cloud connectors and Webhooks.
- Develop, test and troubleshoot custom CBN parsers to normalize non‑standard logs into the Unified Data Model.
- Build dashboards to monitor ingestion rates, latency and data loss, and maintain system health.
- Design and code automated incident response playbooks in Sentinel SOAR with Python and visual builders.
- Create and maintain API integrations between Sentinel SOAR and firewalls, EDR, IAM and ticketing systems.
- Configure case management, custom fields, stages and SLA tracking to match SOC workflows.
- Manage RBAC, threat‑intel feed ingestion (Mandiant, VirusTotal) and continuous rule tuning with analysts.
- Collaborate with cloud architects to configure logging and Pub/Sub pipelines, and coordinate forwarder deployment on‑premises.
- Work with network engineers to resolve connectivity issues that affect telemetry delivery.
Required profile
- Bachelor’s degree in Computer Science, IT, Cybersecurity or equivalent.
- 3–5 years of hands‑on experience with security engineering, SIEM and SOAR platforms.
- Azure Sentinel certification or equivalent SIEM certification; security certifications such as Security+, CySA+, CEH, CISSP or GCIH are a plus.
- Proven ability to translate analyst workflows into automated playbooks.
Required skills
- Python programming
- Azure Sentinel and Sentinel SOAR
- Bind Plane Forwarders, Cloud‑to‑Cloud connectors, Webhooks
- CBN parser development and Unified Data Model (UDM)
- RBAC management
- Mandiant and VirusTotal threat‑intel integration
- YARA‑L rule tuning
- Google Cloud Platform (GCP), Amazon Web Services (AWS), Microsoft Azure
- Pub/Sub and Google SecOps platform
Questions fréquentes
لماذا تبلغ عن هذا العرض؟
اكتشف المزيد
الرواتب والأدلة وعمليات البحث في قطر.
قدم طلبك في 30 ثانية
أدخل بريدك الإلكتروني للتقديم. سيتم إنشاء حساب تلقائياً.
بالمتابعة، أنت توافق على شروط الاستخدام.
لديك حساب بالفعل؟ تسجيل الدخول
عزز فرصك
حمّل سيرتك الذاتية وسنقترح عليك الوظائف التي تناسب ملفك.
جاري تحليل سيرتك الذاتية...
MEEZA QSTP
Doha