Senior Security Engineer - Microsoft Sentinel SIEM
Bengaluru, Karnataka, India
We Help the World Be Everyday Ready™
Today's threatscape is relentless. So are we. At Cyderes, we build practical Identity & Access Management (IAM), Exposure Management, and risk programs, helping organizations stop active threats fast with Managed Detection & Response (MDR) that integrates with existing tools. Powering it all is Meridian, our entity fabric that connects identities, assets, and access into one trusted reality. Augmented by AI and driven by seasoned operators, our tireless global team arms organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way.
About the Job:
The Senior Security Engineer – Microsoft Sentinel & Defender XDR is a senior technical authority within Cyderes' Managed Sentinel SIEM and MDR services. You will manage and contribute in advancing detection, platform reliability, and security automation for managed clients.
Beyond daily platform operations, the Senior Security Engineer leads advanced detection engineering, Create optimization and standardisation efforts, and serve as an escalation point for complex ingestion, telemetry, and investigation challenges. This role partners with MDR, SOC, architecture, and customer team members to ensure Microsoft Sentinel and Defender XDR implementations are, cost-effective, and in consideration of
real-world threat activity.
As a trusted technical advisor, you influence platform strategy, mentor junior engineers, and help shape service evolution by identifying gaps, improving alert fidelity, and ensuring scalable automation. You will represent the Cyderes brand through technical leadership, and delivery excellence that meets client expectations.
You will be reporting to Senior Manager, Managed Platforms.
Responsibilities:
- Be the Subject Matter Expert (SME) for Microsoft Sentinel and Microsoft Defender XDR across managed client environments.
- Manage administration, configuration, and lifecycle management of Microsoft Sentinel and Defender XDR platforms.
- Lead onboarding and integration of new data sources, ensuring connectivity, parsing, normalisation, and visibility in Log Analytics.
- Monitor platform health, increase log ingestion, maintain data connectors, and implement cost optimization strategies.
- Design, and tune advanced detections, analytics rules, and threat hunting use cases using KQL.
- Improve detection effectiveness through MITRE ATT&CK mapping, correlation, enrichment, and false-positive reduction.
- Architect and maintain SOAR automation using Azure Logic Apps for incident response and operational efficiency.
- Troubleshoot and resolve complex telemetry, ingestion, and integration issues across Microsoft and third-party security platforms.
- Develop dashboards, workbooks, runbooks, SOPs, and technical documentation to support security operations.
- Provide technical leadership, mentor junior engineers, and contribute to platform standardisation and best practices.
- Collaborate with partners on security architecture, telemetry strategy, and platform improvements.
- Stay current with Microsoft security technologies, new threats, and industry best practices.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent experience).
- 5+ years of experience in Security Operations, SOC, or Security Engineering roles.
- Minimum 3 years of hands-on experience with Microsoft Sentinel.
- Expertise in Microsoft Defender XDR and its security solutions.
- Experience working in MSSP, MDR, or customer-facing security environments.
- Experience supporting multi-tenant environments using Azure Lighthouse.
- Proficiency in KQL, detection engineering, and threat hunting.
- Hands-on experience with Azure Logic Apps, REST APIs, and PowerShell or Python scripting.
- Experience with Windows/Linux logs, Entra ID (Azure AD), networking fundamentals, and authentication technologies.
- Experience with the MITRE ATT&CK framework and SOC operational processes.
- Translate security telemetry into relevant detections and response workflows.
- Experience in troubleshooting, documentation, and partner management skills.
- We prefer relevant certifications such as SC-200, AZ-500, SC-100, CompTIA Security+ & Microsoft Defender certifications
#LI-Hybrid
This is a hybrid remote/in-office role.
WHY CYDERES?
Benefits that go beyond the basics, we support our people so they can do their best work.
✔ Medical Insurance - Employee + dependents covered
✔ Life Insurance - Protection for what matters most
✔ Retirement Match Program - We invest in your future
✔ Hybrid Work Model - 2–3 days in office
✔ Maternity & Paternity Leave - Time for the moments that matter
✔ Paid Time Off - PTO + sick & casual leave
✔ Bereavement & Volunteer Time - Give back to your community
✔ Professional Development - Reimbursement program
✔ LinkedIn L&D Platform - Thousands of courses at your fingertips
✔ Mobile Phone Reimbursement - Stay connected, on us