Security SME(TESCO)
Zensar.com
Office
India
Full Time
Job Title: SOC Platform Engineer Position Summary:
We are seeking a highly skilled SOC Platform Engineer with a strong background in Microsoft Sentinel, Python automation, and notebook-based threat hunting. This individual contributor role is responsible for engineering and optimizing SOC platform capabilities, supporting SOC practice activities, and enabling advanced threat detection, incident response, and security analytics in cloud-native environments.
Job Description:- Design, deploy, and manage the Microsoft Sentinel SIEM platform to monitor and analyze security events and logs.
- Configure and customize SIEM rules, alerts, and reports for effective threat detection and response.
- Implement logging and auditing across cloud infrastructure using Azure Sentinel.
- Build automated workflows using Logic Apps, Azure Functions, and Python scripts to support incident response and remediation.
- Develop high-confidence correlation rules using diverse data sources and threat use cases.
- Integrate threat intelligence feeds into Sentinel analytics and SOAR workflows.
- Onboard and normalize security logs into Azure Log Analytics Workspace.
- Create incident response use cases and playbooks tailored to organizational needs.
- Conduct automated threat hunting using Jupyter Notebooks integrated with Sentinel and Microsoft Defender.
- Provide remediation recommendations for manual and automated response gaps.
- Collaborate with SOC analysts, threat hunters, and stakeholders to align platform capabilities with operational needs.
- Continuously assess data coverage and identify areas for improvement in Sentinel configuration.
- Maintain technical documentation and process guides related to Azure Sentinel operations.
- Support SOC practice activities, including onboarding new clients, developing reusable platform components, and contributing to SOC maturity initiatives.
- Lead engineering efforts for Microsoft Sentinel deployment and optimization in complex environments.
- Collaborate with cross-functional teams to ensure seamless integration of security tools and telemetry sources.
- Develop and maintain detection use cases, correlation rules, and alerting logic.
- Support SOC operations through automation, enrichment, and performance tuning.
- Contribute to SOC practice development, including playbook standardization, platform templates, and onboarding frameworks.
- Ensure platform compliance with security policies, governance, and regulatory standards.
- Stay current with emerging threats, Sentinel features, and cloud security trends.
- Provide technical guidance and knowledge sharing across SOC and platform engineering teams.
- Proven hands-on experience with Microsoft Sentinel and Azure-native security services.
- Strong understanding of SIEM/SOAR workflows, threat detection, and incident response.
- Experience with Splunk and CrowdStrike Next-Generation SIEM is a plus.
- Proficiency in Python scripting for SOC automation and Jupyter Notebooks for threat hunting.
- Experience with KQL, Logic Apps, PowerShell, and Azure Functions.
- Excellent communication and collaboration skills.
- Relevant certifications such as Microsoft Certified: Security Operations Analyst, Azure Security Engineer Associate, CISSP, or CISM are preferred.
Security SME(TESCO)
Office
India
Full Time
September 20, 2025