Microsoft Sentinel Log Engineer

  •  Reference Number: 29734
  •  Job Published: 08 October 2026
  •  Form of employment: Contract
  •  Apply by: 08 November 2026

Job Description

Location: 100% remote work


Responsibilities: 

•    Onboard on-prem servers to Sentinel with Azure Arc and AMA. Validate log coverage and fix any servers that aren't reporting.
•    Design and build the collection layer for devices that can't run the agent. This means syslog/CEF forwarders behind load balancers in Azure, built for scale and fault tolerance.
•    Close Azure and AWS logging gaps by connecting control-plane and data-plane logs to Sentinel across all tenants and accounts. 
•    Optimize log routing and cost. This covers DCRs, table routing, and moving lower-value logs to the Sentinel data lake tier while still meeting the 1-year retention requirement.
•    Build coverage monitoring with dashboards and alerts that show agent health, onboarding against inventory, and gaps in log sources.
•    Document standards and hand over logging standards, runbooks and architecture diagrams to the InfoSec/SOE team.


Requirements:
•    5+ years in SIEM or security logging engineering, including at least 3 years with Microsoft Sentinel / Log Analytics.
•    Hands-on Azure Arc and Azure Monitor Agent deployment at scale. This includes Data Collection Rules, Private Link/AMPLS and troubleshooting connectivity.
•    Has designed and run syslog/CEF forwarder architecture for firewalls, switches, routers and appliances. This includes HA, load balancing and throughput sizing.
•    Azure Policy for at-scale agent and DCR deployment across multiple tenants and management groups.
•    Strong KQL for validating ingestion, checking coverage and finding gaps.
•    Strong Linux knowledge.
•    Cloud logging: Azure diagnostic, activity and resource logs, plus AWS CloudTrail, VPC Flow Logs and S3 data events through the Sentinel connectors.
•    Sentinel cost and retention design: table tiers, the data lake, filtering and transformations.
•    Comfortable with automated deployment using Ansible, GPO or scripting (PowerShell/Python), within a formal change process.
•    Background in networking, such as Cisco ASA, Palo Alto, DNS and firewall rules for agent connectivity.
•    Has handled logging for managed or customer-facing environments.
•    Certifications such as SC-200, AZ-500 or AZ-104. AWS Security Specialty is a plus.


Our offer:
•    MultiSport Plus
•    Group insurance
•    Medicover Premium

Company Description

Experis to światowy lider rekrutacji specjalistów i kadry zarządzającej w kluczowych obszarach IT. Z nami znajdziesz konkurencyjne oferty zatrudnienia oraz ciekawe projekty IT skierowane zarówno do ekspertów z wieloletnim doświadczeniem, jak i osób, które dopiero zaczynają swoją przygodę w branży IT.

We offer recruitment of managers and highly qualified consultants with expertise in IT.Experis is part of ManpowerGroup and has been named one of the world's most ethical companies.
Warszawa, Mazowieckie
The employment agency - Certificate No. 412