Base Career helps you apply smarter for this job.
Key skills for this role
We are looking for a technically strong and process-driven SIEM Integration & Engineering Specialist with proven experience in Microsoft Sentinel to lead and execute end-to-end integration, onboarding, log parsing, transformation, and ingestion optimization activities. You will own the engineering lifecycle of log source integration, tuning, troubleshooting ingestion issues, and developing reusable automation/SOPs to support multiple enterprise and MSSP customers.
We are looking for a technically strong and process-driven SIEM Integration & Engineering Specialist with proven experience in Microsoft Sentinel to lead and execute end-to-end integration, onboarding, log parsing, transformation, and ingestion optimization activities. You will own the engineering lifecycle of log source integration, tuning, troubleshooting ingestion issues, and developing reusable automation/SOPs to support multiple enterprise and MSSP customers.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Identify and resolve log duplication issues using correlation, diagnostic settings, and parsing analysis.
Choose between agent-based and agentless ingestion strategies; document troubleshooting methods and share reusable configurations.
Design ingestion pipelines considering performance throttling , throughput optimization , and pre-ingestion routing (like log routers, collectors, proxies).
Collaborate with customers to align ingestion design with retention policies and data costs .
Develop and maintain log rotation configurations/scripts for Linux and Windows sources, including detection and remediation of rotation issues.
Create scheduled health checks , KQL rules, and workbooks to detect connector failures, latency, heartbeat gaps, and log drop-offs.
Document common ingestion failure patterns (encoding errors, firewall/network issues, schema mismatches) with precise troubleshooting playbooks .
Maintain playbooks for character encoding issues (UTF-8, BOM) and solutions for encrypted log payloads or malformed syslog headers.
Lead Windows Event Forwarding (WEF) implementation via GPO with enhanced configurations, filtering, and troubleshooting best practices.
Configure and tune Sysmon, Syslog-NG, Rsyslog , and Logstash for Linux and application logs; implement JDBC or file-based DB integrations.
Create reusable templates for schema mapping and log parsing pipelines for non-standard applications and tools.
Build PowerShell/Bash scripts to automate onboarding of frequently used log sources.
Maintain or create ARM/Bicep templates for Sentinel infrastructure provisioning, including DCRs, diagnostic settings, and analytics rules.
Script or pipeline complex log transformations, parsing pipelines , and even alert tuning workflows (e.g., via Logic Apps).
Define and manage RBAC roles for Sentinel, data source connectors, and ingestion tools.
Implement Managed Identity-based ingestion for secure connections (e.g., Azure Function Apps, Logstash, REST APIs).
Audit and document access control , permission requirements, and secure token-based configurations used for custom integrations.
Master log source onboarding guidebook
SOP library for custom and native integrations
Collection of scripts and templates (DCR, KQL rules, health monitors, log rotation)
Workbook for ingestion health monitoring
Repository of common failure scenarios and fix playbooks
Verified company details for this employer are not available yet.
Full-time
Mid · 3+ years experience
Onsite
Apply faster on company sites with our extension.