Microsoft Sentinel Log Engineer

  •  Numer ref.: 29734
  •  Oferta opublikowana: 08 października 2026
  •  Typ pracy: Kontrakt
  •  Ważna do: 08 listopada 2026

Opis Pracy

Location: 100% remote work


Responsibilities: 

•    Onboard on-prem servers to Sentinel with Azure Arc and AMA. Validate log coverage and fix any servers that aren't reporting.
•    Design and build the collection layer for devices that can't run the agent. This means syslog/CEF forwarders behind load balancers in Azure, built for scale and fault tolerance.
•    Close Azure and AWS logging gaps by connecting control-plane and data-plane logs to Sentinel across all tenants and accounts. 
•    Optimize log routing and cost. This covers DCRs, table routing, and moving lower-value logs to the Sentinel data lake tier while still meeting the 1-year retention requirement.
•    Build coverage monitoring with dashboards and alerts that show agent health, onboarding against inventory, and gaps in log sources.
•    Document standards and hand over logging standards, runbooks and architecture diagrams to the InfoSec/SOE team.


Requirements:
•    5+ years in SIEM or security logging engineering, including at least 3 years with Microsoft Sentinel / Log Analytics.
•    Hands-on Azure Arc and Azure Monitor Agent deployment at scale. This includes Data Collection Rules, Private Link/AMPLS and troubleshooting connectivity.
•    Has designed and run syslog/CEF forwarder architecture for firewalls, switches, routers and appliances. This includes HA, load balancing and throughput sizing.
•    Azure Policy for at-scale agent and DCR deployment across multiple tenants and management groups.
•    Strong KQL for validating ingestion, checking coverage and finding gaps.
•    Strong Linux knowledge.
•    Cloud logging: Azure diagnostic, activity and resource logs, plus AWS CloudTrail, VPC Flow Logs and S3 data events through the Sentinel connectors.
•    Sentinel cost and retention design: table tiers, the data lake, filtering and transformations.
•    Comfortable with automated deployment using Ansible, GPO or scripting (PowerShell/Python), within a formal change process.
•    Background in networking, such as Cisco ASA, Palo Alto, DNS and firewall rules for agent connectivity.
•    Has handled logging for managed or customer-facing environments.
•    Certifications such as SC-200, AZ-500 or AZ-104. AWS Security Specialty is a plus.


Our offer:
•    MultiSport Plus
•    Group insurance
•    Medicover Premium

Opis Firmy

Experis to światowy lider rekrutacji specjalistów i kadry zarządzającej w kluczowych obszarach IT. Z nami znajdziesz konkurencyjne oferty zatrudnienia oraz ciekawe projekty IT skierowane zarówno do ekspertów z wieloletnim doświadczeniem, jak i osób, które dopiero zaczynają swoją przygodę w branży IT.

Oferujemy rekrutacje menedżerów i wysoko wykwalifikowanych konsultantów z doświadczeniem w branży IT. Experis jest częścią ManpowerGroup i został uznany za jedną z najbardziej etycznych firm na świecie.
Warszawa, Mazowieckie
Agencja zatrudnienia – nr certyfikatu 412