Job Description SIEM Architect Required Technical Skill Set** Microsoft Sentinel SIEM Architect with strong expertise in Azure security technologies. Desired Experience Range** 10-15 YRS Location of Requirement Chennai Desired Competencies (Technical/Behavioral Competency) Must-Have We are seeking an experienced Microsoft Sentinel SIEM Architect with strong expertise in Azure security technologies, AI-driven security (Azure OpenAI), and Microsoft Security Copilot. The ideal candidate will design, implement, and optimize modern cloud-native SIEM/SOAR solutions, while leveraging AI and automation to enhance threat detection, response, and SOC efficiency. Good-to-Have - Use Azure OpenAI for threat analysis, summarization, KQL/playbook generation - Leverage Security Copilot for investigation and response - Build AI workflows using prompt engineering & automation Responsibility of / Expectations from the Role 1 Design and implement end-to-end Sentinel architectures. Define ingestion, normalization (ASIM), and retention strategies. Architect multi-region & multi-tenant solutions. 2 Develop HLD & LLD documentation, Integrate Azure, M365, Defender, on-prem (Syslog/CEF), AWS, GCP. 3 Configure AMA, Event Hub, APIs, Logic Apps, Implement log filtering, transformation, enrichment. 4 Develop HLD & LLD documentation, Integrate Azure, M365, Defender, on-prem (Syslog/CEF), AWS, GCP 5 Custom Connector , Application log Source onboarding, Develop KQL-based analytics rules, Implement Fusion (ML) and NRT detections, Map to MITRE ATT&CK, Tune alerts and reduce false positives. 6 Build Logic Apps playbooks, Automate triage, containment (IP/user actions), ticketing integration, Define automation lifecycle rules. 7 Design L1/L2/L3 SOC workflows, Define severity, escalation, classification, Support threat hunting & incident response. 8 Implement RBAC, PIM, Ensure ISO 27001, NIST, CIS compliance, Align logging with regulatory requirements. 9 Optimize ingestion filtering, Manage retention (hot/archive), Monitor cost & performance efficiency. 10 Preferred Certifications - SC-100 – Microsoft Cybersecurity Architect - SC-200 – Security Operations Analyst - AZ-500 – Azure Security Engineer - Azure AI / OpenAI certifications (preferred) 11 Key Competencies - Strong analytical & problem-solving skills - Enterprise-scale architecture design - AI-driven SOC transformation expertise - Stakeholder & SOC communication skills
SIEM Architect • Chennai, India, IN