एम
Security Infrastructure Engineer - Sentinel
Doha, Doha Municipality, Qatar · पूरा समय
अप्लाय करने वाले प्रथम बनिए
- अनुभव
- 3-5 वर्ष
- वेतन
- —
- उद्घाटन
- 1
- की तैनाती
- 2 पहले
- कार्य मोड
- कार्यालय में हूँ
- शिक्षा
- Bachelor's degree in computer science, IT, cybersecurity, or a related discipline
- फिर शुरू करना
- आवेदन करना आवश्यक है
आप कहाँ काम करेंगे
नौकरी का विवरण
Role Overview
We are seeking a Security Infrastructure Engineer specialized in Sentinel to join our team in Doha, Qatar. This role involves designing and maintaining data ingestion pipelines from multiple cloud providers and on-premises environments, developing custom log parsers, automating incident response workflows, and managing platform health and access control for the security operations center (SOC).
Key Responsibilities
- Architect and maintain data ingestion pipelines across GCP, AWS, Azure, and on-premises using Bind Plane Forwarders, Cloud-to-Cloud connectors, and Webhooks.
- Develop and troubleshoot custom parsers to normalize diverse log sources into a Unified Data Model, ensuring data quality and integrity.
- Create dashboards to monitor telemetry ingestion, latency, and data drops to maintain high-quality, actionable SIEM data.
- Design and implement automated incident response playbooks using Python and visual tools within Sentinel SOAR.
- Build and maintain API integrations between Sentinel SOAR and external security tools such as firewalls, endpoint detection and response (EDR), identity and access management (IAM), and ticketing systems.
- Optimize workflows by automating repetitive tasks including artifact enrichment, evidence collection, and initial containment steps.
- Customize SOAR platform case management features including fields, stages, and SLA tracking to align with SOC operational needs.
- Monitor system health to prevent data loss and maintain latency within acceptable limits.
- Manage role-based access control to secure sensitive data access appropriately for analysts.
- Integrate threat intelligence feeds like Mandiant and VirusTotal to keep detection capabilities current with emerging threats.
- Collaborate with SOC Tier 1 and Tier 2 analysts to fine-tune YARA-L rules by analyzing alert performance and false positives.
- Gather requirements by interviewing incident responders and converting workflows into automated Sentinel SOAR playbooks.
- Conduct training sessions on using Unified Data Model Search and Microsoft Sentinel for faster investigations.
- Work with cloud architects to configure logging and Pub/Sub for seamless telemetry export to Google SecOps platform.
- Coordinate deployment and maintenance of Bind Plane Forwarders within on-premises infrastructure.
- Partner with network engineers to troubleshoot connectivity or firewall issues affecting telemetry flows.
Required Qualifications and Experience
- Bachelor’s degree in Computer Science, IT, Cybersecurity, or a related discipline.
- Certification in SIEM technologies, specifically Azure Sentinel.
- Preferred certifications include Security+, CySA+, CEH, CISSP, or GCIH.
- 3 to 5 years of practical experience in Security Engineering, SOC Automation, DevOps, Security Operations, or Infrastructure Security.
Technical Skills
- Strong expertise in architecting and administrating enterprise SIEM/SOAR platforms such as Splunk, Azure Sentinel, or QRadar, with 1–2 years focused on Google SecOps (Chronicle).
- Advanced Python programming skills for workflow automation and custom API connector development.
- Experience securing Google Cloud Platform environments including VPC controls, IAM, and Cloud Logging.
- Proficiency in SQL (BigQuery), YARA/YARA-L rule writing, and Bash scripting.
- Familiarity with cybersecurity frameworks such as MITRE ATT&CK and NIST Cybersecurity Framework.
- Hands-on exposure to tools such as Git for version control, Terraform for infrastructure as code, and container orchestration with Docker and Kubernetes.
- In-depth understanding of data standards and formats including JSON, Protobuf, and regular expressions for log parsing.
Soft Skills
- Strong analytical and problem-solving abilities.
- Effective communication skills capable of bridging technical and non-technical audiences.
- Ability to independently prioritize tasks and meet deadlines efficiently.
- Keen attention to detail and commitment to thorough documentation and structured processes.