Agencja zatrudnienia – nr certyfikatu 412
Microsoft Sentinel Log Engineer
Numer ref.: 29734
Oferta opublikowana: 08 października 2026
Typ pracy: Kontrakt
Ważna do: 08 listopada 2026
Opis Pracy
Location: 100% remote work
Responsibilities:
• Onboard on-prem servers to Sentinel with Azure Arc and AMA. Validate log coverage and fix any servers that aren't reporting.
• Design and build the collection layer for devices that can't run the agent. This means syslog/CEF forwarders behind load balancers in Azure, built for scale and fault tolerance.
• Close Azure and AWS logging gaps by connecting control-plane and data-plane logs to Sentinel across all tenants and accounts.
• Optimize log routing and cost. This covers DCRs, table routing, and moving lower-value logs to the Sentinel data lake tier while still meeting the 1-year retention requirement.
• Build coverage monitoring with dashboards and alerts that show agent health, onboarding against inventory, and gaps in log sources.
• Document standards and hand over logging standards, runbooks and architecture diagrams to the InfoSec/SOE team.
Requirements:
• 5+ years in SIEM or security logging engineering, including at least 3 years with Microsoft Sentinel / Log Analytics.
• Hands-on Azure Arc and Azure Monitor Agent deployment at scale. This includes Data Collection Rules, Private Link/AMPLS and troubleshooting connectivity.
• Has designed and run syslog/CEF forwarder architecture for firewalls, switches, routers and appliances. This includes HA, load balancing and throughput sizing.
• Azure Policy for at-scale agent and DCR deployment across multiple tenants and management groups.
• Strong KQL for validating ingestion, checking coverage and finding gaps.
• Strong Linux knowledge.
• Cloud logging: Azure diagnostic, activity and resource logs, plus AWS CloudTrail, VPC Flow Logs and S3 data events through the Sentinel connectors.
• Sentinel cost and retention design: table tiers, the data lake, filtering and transformations.
• Comfortable with automated deployment using Ansible, GPO or scripting (PowerShell/Python), within a formal change process.
• Background in networking, such as Cisco ASA, Palo Alto, DNS and firewall rules for agent connectivity.
• Has handled logging for managed or customer-facing environments.
• Certifications such as SC-200, AZ-500 or AZ-104. AWS Security Specialty is a plus.
Our offer:
• MultiSport Plus
• Group insurance
• Medicover Premium
Responsibilities:
• Onboard on-prem servers to Sentinel with Azure Arc and AMA. Validate log coverage and fix any servers that aren't reporting.
• Design and build the collection layer for devices that can't run the agent. This means syslog/CEF forwarders behind load balancers in Azure, built for scale and fault tolerance.
• Close Azure and AWS logging gaps by connecting control-plane and data-plane logs to Sentinel across all tenants and accounts.
• Optimize log routing and cost. This covers DCRs, table routing, and moving lower-value logs to the Sentinel data lake tier while still meeting the 1-year retention requirement.
• Build coverage monitoring with dashboards and alerts that show agent health, onboarding against inventory, and gaps in log sources.
• Document standards and hand over logging standards, runbooks and architecture diagrams to the InfoSec/SOE team.
Requirements:
• 5+ years in SIEM or security logging engineering, including at least 3 years with Microsoft Sentinel / Log Analytics.
• Hands-on Azure Arc and Azure Monitor Agent deployment at scale. This includes Data Collection Rules, Private Link/AMPLS and troubleshooting connectivity.
• Has designed and run syslog/CEF forwarder architecture for firewalls, switches, routers and appliances. This includes HA, load balancing and throughput sizing.
• Azure Policy for at-scale agent and DCR deployment across multiple tenants and management groups.
• Strong KQL for validating ingestion, checking coverage and finding gaps.
• Strong Linux knowledge.
• Cloud logging: Azure diagnostic, activity and resource logs, plus AWS CloudTrail, VPC Flow Logs and S3 data events through the Sentinel connectors.
• Sentinel cost and retention design: table tiers, the data lake, filtering and transformations.
• Comfortable with automated deployment using Ansible, GPO or scripting (PowerShell/Python), within a formal change process.
• Background in networking, such as Cisco ASA, Palo Alto, DNS and firewall rules for agent connectivity.
• Has handled logging for managed or customer-facing environments.
• Certifications such as SC-200, AZ-500 or AZ-104. AWS Security Specialty is a plus.
Our offer:
• MultiSport Plus
• Group insurance
• Medicover Premium
Opis Firmy
Experis to światowy lider rekrutacji specjalistów i kadry zarządzającej w kluczowych obszarach IT. Z nami znajdziesz konkurencyjne oferty zatrudnienia oraz ciekawe projekty IT skierowane zarówno do ekspertów z wieloletnim doświadczeniem, jak i osób, które dopiero zaczynają swoją przygodę w branży IT.
Oferujemy rekrutacje menedżerów i wysoko wykwalifikowanych konsultantów z doświadczeniem w branży IT. Experis jest częścią ManpowerGroup i został uznany za jedną z najbardziej etycznych firm na świecie.

