Security Tooling Engineer
Core
Maintaining and evolving the organization's security monitoring and endpoint protection capabilities, with a focus on Microsoft Defender for Endpoint.
Role type
Security Tooling Engineer (Microsoft Defender/Sentinel)
Builds
Security monitoring coverage, automation, and operational effectiveness for Microsoft Defender and Sentinel
Domain
Cybersecurity / Cloud Security (Azure)
Required skills
Microsoft Defender for Endpoint, Microsoft Sentinel, Azure cloud security, log management, data ingestion, audit support, Infrastructure as Code (IaC)
Preferred skills
AI-driven use case development, stakeholder collaboration, incident response support, team mentorship (via careerplan.io/jobs/R20476-security-tooling-engineer-at-mgpru)
Technologies
Microsoft Defender for Endpoint, Microsoft Sentinel, Azure, Logstash
Responsibilities
Ensure Microsoft Defender platform health and alignment with security requirements; Develop and improve Microsoft Sentinel capabilities; Support onboarding of new applications for security monitoring; Maintain security log collection and ingestion capabilities; Participate in incident response and investigations; Mentor junior team members
Seniority
Mid-level, hands-on IC