Back to search
HCLTech Linkedin · Posted 8d ago

L3 Microsoft Sentinel & Defender Endpoint Platform Engineer

Bulgaria

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

HCLTech is a global technology company, home to more than 219,000+ people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2024 totaled $13.4 billion.


Role Overview:

We are looking for an experienced and strategic L3 Microsoft Sentinel & Defender Endpoint Platform Engineer to lead the development, optimization, and end-to-end management of SIEM and EDR platforms. This role focuses on platform architecture, detection engineering, automation, integration, and continuous improvement of security operations capabilities.

Experience:

Overall 10+ years of industry experience, minimum 5+ years in SIEM/EDR platform management, with strong expertise in Microsoft Sentinel, Defender for Endpoint, and SOC platform engineering.

Key Responsibilities:

  • Architect, design, and implement end-to-end SIEM and EDR platform capabilities, including Microsoft Sentinel and Defender for Endpoint.
  • Lead platform architecture and integration of endpoint, identity, cloud, and network data sources into Sentinel.
  • Design and maintain scalable SIEM-EDR integration ensuring high-fidelity telemetry ingestion and correlation.
  • Develop, implement, and manage advanced detection use cases aligned to MITRE ATT&CK framework.
  • Drive use case lifecycle management including onboarding, validation, optimization, and decommissioning.
  • Continuously fine-tune detection logic, analytics rules, and ASR policies to reduce false positives and improve detection quality.
  • Own and optimize detection engineering practices including KQL-based analytics development and performance tuning.
  • Design, develop, and maintain automation workflows using Logic Apps and SOAR capabilities for incident response.
  • Implement automated response, enrichment, and orchestration across Sentinel and Defender platforms.
  • Lead platform optimization initiatives including cost optimization, ingestion control, and query performance tuning.
  • Define and implement endpoint protection policies, configurations, and security baselines.
  • Develop and maintain HLD/LLD for SIEM and EDR platforms and integrations.
  • Drive EDR agent deployment strategies, onboarding/offboarding lifecycle, and endpoint visibility coverage.
  • Manage and optimize endpoint detection policies, exclusion handling, and exception management.
  • Define SLA metrics, monitoring frameworks, and reporting structures for SIEM and EDR services.
  • Ensure compliance alignment with regulatory, security, and audit requirements across platforms.
  • Lead integration testing, validation, and release management for platform updates and new capabilities.
  • Monitor and manage SIEM and EDR platforms including alerts, incidents, and system health.
  • Execute containment, remediation, and recovery actions for endpoint and security incidents.
  • Manage quarantine, isolation, and response actions for compromised endpoints.
  • Conduct continuous platform performance monitoring and capacity planning.
  • Oversee platform tuning, configuration optimization, and feature enablement aligned to business needs.
  • Regularly update and synchronize indicators of compromise (IoCs) across SIEM/XDR platforms.
  • Support major incident investigations and provide technical leadership during critical incidents.
  • Maintain and enhance playbooks, runbooks, and operational documentation.
  • Perform periodic validation of detection coverage and endpoint protection effectiveness.
  • Track, analyze, and report platform performance, SLA compliance, and operational metrics.
  • Coordinate with SOC, infrastructure, and security teams to ensure seamless service delivery.
  • Manage vendor interactions, escalations, and feature evaluations for continuous improvement.
  • Drive adoption of new features, capabilities, and improvements across Sentinel and Defender platforms.


What we offer:

• Food vouchers.

• Competitive salary and performance bonuses.

• Opportunity for career progression.

• Social benefits package.

• Professional on-boarding and on-going trainings.


Are you willing to build up your career with us? - We’ll be happy to receive your resume in English! *Your personal data is secure with us. ** Only candidates selected for interview will be contacted HCLTech provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by state or local laws.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search