The employment agency - Certificate No. 412
Microsoft Sentinel Log Engineer
Reference Number: 29734
Job Published: 08 October 2026
Form of employment: Contract
Apply by: 08 November 2026
Job Description
Location: 100% remote work
Responsibilities:
• Onboard on-prem servers to Sentinel with Azure Arc and AMA. Validate log coverage and fix any servers that aren't reporting.
• Design and build the collection layer for devices that can't run the agent. This means syslog/CEF forwarders behind load balancers in Azure, built for scale and fault tolerance.
• Close Azure and AWS logging gaps by connecting control-plane and data-plane logs to Sentinel across all tenants and accounts.
• Optimize log routing and cost. This covers DCRs, table routing, and moving lower-value logs to the Sentinel data lake tier while still meeting the 1-year retention requirement.
• Build coverage monitoring with dashboards and alerts that show agent health, onboarding against inventory, and gaps in log sources.
• Document standards and hand over logging standards, runbooks and architecture diagrams to the InfoSec/SOE team.
Requirements:
• 5+ years in SIEM or security logging engineering, including at least 3 years with Microsoft Sentinel / Log Analytics.
• Hands-on Azure Arc and Azure Monitor Agent deployment at scale. This includes Data Collection Rules, Private Link/AMPLS and troubleshooting connectivity.
• Has designed and run syslog/CEF forwarder architecture for firewalls, switches, routers and appliances. This includes HA, load balancing and throughput sizing.
• Azure Policy for at-scale agent and DCR deployment across multiple tenants and management groups.
• Strong KQL for validating ingestion, checking coverage and finding gaps.
• Strong Linux knowledge.
• Cloud logging: Azure diagnostic, activity and resource logs, plus AWS CloudTrail, VPC Flow Logs and S3 data events through the Sentinel connectors.
• Sentinel cost and retention design: table tiers, the data lake, filtering and transformations.
• Comfortable with automated deployment using Ansible, GPO or scripting (PowerShell/Python), within a formal change process.
• Background in networking, such as Cisco ASA, Palo Alto, DNS and firewall rules for agent connectivity.
• Has handled logging for managed or customer-facing environments.
• Certifications such as SC-200, AZ-500 or AZ-104. AWS Security Specialty is a plus.
Our offer:
• MultiSport Plus
• Group insurance
• Medicover Premium
Responsibilities:
• Onboard on-prem servers to Sentinel with Azure Arc and AMA. Validate log coverage and fix any servers that aren't reporting.
• Design and build the collection layer for devices that can't run the agent. This means syslog/CEF forwarders behind load balancers in Azure, built for scale and fault tolerance.
• Close Azure and AWS logging gaps by connecting control-plane and data-plane logs to Sentinel across all tenants and accounts.
• Optimize log routing and cost. This covers DCRs, table routing, and moving lower-value logs to the Sentinel data lake tier while still meeting the 1-year retention requirement.
• Build coverage monitoring with dashboards and alerts that show agent health, onboarding against inventory, and gaps in log sources.
• Document standards and hand over logging standards, runbooks and architecture diagrams to the InfoSec/SOE team.
Requirements:
• 5+ years in SIEM or security logging engineering, including at least 3 years with Microsoft Sentinel / Log Analytics.
• Hands-on Azure Arc and Azure Monitor Agent deployment at scale. This includes Data Collection Rules, Private Link/AMPLS and troubleshooting connectivity.
• Has designed and run syslog/CEF forwarder architecture for firewalls, switches, routers and appliances. This includes HA, load balancing and throughput sizing.
• Azure Policy for at-scale agent and DCR deployment across multiple tenants and management groups.
• Strong KQL for validating ingestion, checking coverage and finding gaps.
• Strong Linux knowledge.
• Cloud logging: Azure diagnostic, activity and resource logs, plus AWS CloudTrail, VPC Flow Logs and S3 data events through the Sentinel connectors.
• Sentinel cost and retention design: table tiers, the data lake, filtering and transformations.
• Comfortable with automated deployment using Ansible, GPO or scripting (PowerShell/Python), within a formal change process.
• Background in networking, such as Cisco ASA, Palo Alto, DNS and firewall rules for agent connectivity.
• Has handled logging for managed or customer-facing environments.
• Certifications such as SC-200, AZ-500 or AZ-104. AWS Security Specialty is a plus.
Our offer:
• MultiSport Plus
• Group insurance
• Medicover Premium
Company Description
Experis to światowy lider rekrutacji specjalistów i kadry zarządzającej w kluczowych obszarach IT. Z nami znajdziesz konkurencyjne oferty zatrudnienia oraz ciekawe projekty IT skierowane zarówno do ekspertów z wieloletnim doświadczeniem, jak i osób, które dopiero zaczynają swoją przygodę w branży IT.
We offer recruitment of managers and highly qualified consultants with expertise in IT.Experis is part of ManpowerGroup and has been named one of the world's most ethical companies.

