SIEM Architect
Job Description
SIEM Architect
\nRequired Technical Skill Set**
\nMicrosoft Sentinel SIEM Architect with strong expertise in Azure security technologies.
\nDesired Experience Range**
\n10-15 YRS
\nLocation of Requirement
\nChennai
\nDesired Competencies (Technical/Behavioral Competency)
\nMust-Have
\nWe are seeking an experienced Microsoft Sentinel SIEM Architect with strong expertise in Azure security technologies, AI-driven security (Azure OpenAI), and Microsoft Security Copilot. The ideal candidate will design, implement, and optimize modern cloud-native SIEM/SOAR solutions, while leveraging AI and automation to enhance threat detection, response, and SOC efficiency.
\nGood-to-Have
\n- \n
- Use Azure OpenAI for threat analysis, summarization, KQL/playbook generation \n
- Leverage Security Copilot for investigation and response \n
- Build AI workflows using prompt engineering & automation \n
Responsibility of / Expectations from the Role
\n1
\nDesign and implement end-to-end Sentinel architectures. Define ingestion, normalization (ASIM), and retention strategies. Architect multi-region & multi-tenant solutions.
\n2
\nDevelop HLD & LLD documentation, Integrate Azure, M365, Defender, on-prem (Syslog/CEF), AWS, GCP.
\n3
\nConfigure AMA, Event Hub, APIs, Logic Apps, Implement log filtering, transformation, enrichment.
\n4
\nDevelop HLD & LLD documentation, Integrate Azure, M365, Defender, on-prem (Syslog/CEF), AWS, GCP
\n5
\nCustom Connector , Application log Source onboarding, Develop KQL-based analytics rules, Implement Fusion (ML) and NRT detections, Map to MITRE ATT&CK, Tune alerts and reduce false positives.
\n6
\nBuild Logic Apps playbooks, Automate triage, containment (IP/user actions), ticketing integration, Define automation lifecycle rules.
\n7
\nDesign L1/L2/L3 SOC workflows, Define severity, escalation, classification, Support threat hunting & incident response.
\n8
\nImplement RBAC, PIM, Ensure ISO 27001, NIST, CIS compliance, Align logging with regulatory requirements.
\n9
\nOptimize ingestion filtering, Manage retention (hot/archive), Monitor cost & performance efficiency.
\n10
\nPreferred Certifications
\n- \n
- SC-100 – Microsoft Cybersecurity Architect \n
- SC-200 – Security Operations Analyst \n
- AZ-500 – Azure Security Engineer \n
- Azure AI / OpenAI certifications (preferred) \n
11
\nKey Competencies
\n- \n
- Strong analytical & problem-solving skills \n
- Enterprise-scale architecture design \n
- AI-driven SOC transformation expertise \n
- Stakeholder & SOC communication skills \n