Career / L2 Security Implementation Engineer

L2 Security Implementation Engineer

Cloud Engineering | Mid Level | Full Time | Bangalore | On-site

Job Description

Introduction

We are looking for a skilled L2 Implementation Engineer with 4–5 years of hands on experience deploying and configuring Microsoft Sentinel and Microsoft Defender products. This role focuses entirely on implementation, onboarding, integrations, policy configuration, customer deployments, and technical project delivery-not SOC monitoring.

Key Responsibilities

  • Deploy and configure Log Analytics Workspace, data retention, workspace architecture.Onboard data sources using connectors (Azure services, M365, Defender, Syslog, CEF agents, firewalls, proxies, SaaS apps).Configure Log Analytics Agents / AMA on Windows, Linux, and network appliances.Implement workbooks, dashboards, and basic analytic rules as part of initial setup.Configure and test automation rules & SOAR Playbooks (Logic Apps) to meet customer use cases.Integrate Sentinel with:Microsoft Defender XDRAzure AD / Entra ID logsAzure Activity LogsOn‑prem serversFirewalls (Palo Alto, Fortinet, Checkpoint)
  • Deploy and configure Log Analytics Workspace, data retention, workspace architecture.Onboard data sources using connectors (Azure services, M365, Defender, Syslog, CEF agents, firewalls, proxies, SaaS apps).Configure Log Analytics Agents / AMA on Windows, Linux, and network appliances.Implement workbooks, dashboards, and basic analytic rules as part of initial setup.Configure and test automation rules & SOAR Playbooks (Logic Apps) to meet customer use cases.Integrate Sentinel with:Microsoft Defender XDRAzure AD / Entra ID logsAzure Activity LogsOn‑prem serversFirewalls (Palo Alto, Fortinet, Checkpoint)
  • Deploy and configure Log Analytics Workspace, data retention, workspace architecture.
  • Onboard data sources using connectors (Azure services, M365, Defender, Syslog, CEF agents, firewalls, proxies, SaaS apps).
  • Configure Log Analytics Agents / AMA on Windows, Linux, and network appliances.
  • Implement workbooks, dashboards, and basic analytic rules as part of initial setup.
  • Configure and test automation rules & SOAR Playbooks (Logic Apps) to meet customer use cases.
  • Integrate Sentinel with:
  • Microsoft Defender XDRAzure AD / Entra ID logsAzure Activity LogsOn‑prem serversFirewalls (Palo Alto, Fortinet, Checkpoint)
  • Microsoft Defender XDR
  • Azure AD / Entra ID logs
  • Azure Activity Logs
  • On‑prem servers
  • Firewalls (Palo Alto, Fortinet, Checkpoint)
  • Onboard Windows, macOS, Linux devices using onboarding scripts, Intune, Group Policy.Configure AV, EDR, ASR rules, firewall, network protection, web filtering, and device control.Build and deploy endpoint security baselines using Intune or GPO.
  • Onboard Windows, macOS, Linux devices using onboarding scripts, Intune, Group Policy.Configure AV, EDR, ASR rules, firewall, network protection, web filtering, and device control.Build and deploy endpoint security baselines using Intune or GPO.
  • Onboard Windows, macOS, Linux devices using onboarding scripts, Intune, Group Policy.
  • Configure AV, EDR, ASR rules, firewall, network protection, web filtering, and device control.
  • Build and deploy endpoint security baselines using Intune or GPO.
  • Deploy sensors on Domain Controllers.Configure directory services integration.Validate lateral movement and identity monitoring.
  • Deploy sensors on Domain Controllers.Configure directory services integration.Validate lateral movement and identity monitoring.
  • Deploy sensors on Domain Controllers.
  • Configure directory services integration.
  • Validate lateral movement and identity monitoring.
  • Configure app connectors (O365, AWS, GCP, Salesforce, ServiceNow).Deploy session control, app discovery, conditional access app control.Enable policies for DLP, file governance, and compliance.
  • Configure app connectors (O365, AWS, GCP, Salesforce, ServiceNow).Deploy session control, app discovery, conditional access app control.Enable policies for DLP, file governance, and compliance.
  • Configure app connectors (O365, AWS, GCP, Salesforce, ServiceNow).
  • Deploy session control, app discovery, conditional access app control.
  • Enable policies for DLP, file governance, and compliance.
  • Configure Safe Links, Safe Attachments, anti‑phishing policies, impersonation protection.Integrate O365 signals with Sentinel.
  • Configure Safe Links, Safe Attachments, anti‑phishing policies, impersonation protection.Integrate O365 signals with Sentinel.
  • Configure Safe Links, Safe Attachments, anti‑phishing policies, impersonation protection.
  • Integrate O365 signals with Sentinel.
  • Configure subscriptions, security policies, recommendations & workload protections.Enable defender plans for VMs, storage, SQL, containers, key vault, etc.
  • Configure subscriptions, security policies, recommendations & workload protections.Enable defender plans for VMs, storage, SQL, containers, key vault, etc.
  • Configure subscriptions, security policies, recommendations & workload protections.
  • Enable defender plans for VMs, storage, SQL, containers, key vault, etc.
  • Gather customer requirements and convert them into technical implementation steps.Prepare HLD/LLD documentation, architecture diagrams, implementation plans.Perform POCs, pilots, environment assessments, and configuration validation.Troubleshoot onboarding issues, connector failures, integration errors.Conduct knowledge transfer (KT) sessions to customers post‑deployment.Work with Microsoft Intune for onboarding Defender & deploying policies (if required).Good Power shell and Linux scripting skills
  • Gather customer requirements and convert them into technical implementation steps.Prepare HLD/LLD documentation, architecture diagrams, implementation plans.Perform POCs, pilots, environment assessments, and configuration validation.Troubleshoot onboarding issues, connector failures, integration errors.Conduct knowledge transfer (KT) sessions to customers post‑deployment.Work with Microsoft Intune for onboarding Defender & deploying policies (if required).Good Power shell and Linux scripting skills
  • Gather customer requirements and convert them into technical implementation steps.
  • Prepare HLD/LLD documentation, architecture diagrams, implementation plans.
  • Perform POCs, pilots, environment assessments, and configuration validation.
  • Troubleshoot onboarding issues, connector failures, integration errors.
  • Conduct knowledge transfer (KT) sessions to customers post‑deployment.
  • Work with Microsoft Intune for onboarding Defender & deploying policies (if required).
  • Good Power shell and Linux scripting skills
Requirements & Qualifications

Key Responsibilities

  • Strong experience implementing:Microsoft SentinelDefender for EndpointDefender for IdentityDefender for Office 365Defender for Cloud AppsDefender for Cloud (Azure)Good hands‑on knowledge of:Azure Log AnalyticsKQL (basic‑intermediate for validation)Azure Logic Apps (SOAR playbooks)Azure AD / Entra ID logsStrong understanding of onboarding methods, connectors, log ingestion, and device integrations.
  • Strong experience implementing:Microsoft SentinelDefender for EndpointDefender for IdentityDefender for Office 365Defender for Cloud AppsDefender for Cloud (Azure)Good hands‑on knowledge of:Azure Log AnalyticsKQL (basic‑intermediate for validation)Azure Logic Apps (SOAR playbooks)Azure AD / Entra ID logsStrong understanding of onboarding methods, connectors, log ingestion, and device integrations.
  • Strong experience implementing:
  • Microsoft SentinelDefender for EndpointDefender for IdentityDefender for Office 365Defender for Cloud AppsDefender for Cloud (Azure)
  • Microsoft Sentinel
  • Defender for Endpoint
  • Defender for Identity
  • Defender for Office 365
  • Defender for Cloud Apps
  • Defender for Cloud (Azure)
  • Good hands‑on knowledge of:
  • Azure Log AnalyticsKQL (basic‑intermediate for validation)Azure Logic Apps (SOAR playbooks)Azure AD / Entra ID logs
  • Azure Log Analytics
  • KQL (basic‑intermediate for validation)
  • Azure Logic Apps (SOAR playbooks)
  • Azure AD / Entra ID logs
  • Strong understanding of onboarding methods, connectors, log ingestion, and device integrations.
  • Microsoft Certifications:SC‑200 (Security Operations Analyst) / SC‑300 / AZ‑500 / AZ-900Experience with firewalls, proxies, server logs, API integrations (for Sentinel connectors).
  • Microsoft Certifications:SC‑200 (Security Operations Analyst) / SC‑300 / AZ‑500 / AZ-900Experience with firewalls, proxies, server logs, API integrations (for Sentinel connectors).
  • Microsoft Certifications:
  • SC‑200 (Security Operations Analyst) / SC‑300 / AZ‑500 / AZ-900
  • SC‑200 (Security Operations Analyst) / SC‑300 / AZ‑500 / AZ-900
  • Experience with firewalls, proxies, server logs, API integrations (for Sentinel connectors).
  • Strong communication and customer‑facing skills.Ability to work with delivery teams, architects, and customers.Good documentation skills (HLD/LLD, runbooks).Problem-solving skills and ownership mindset.
  • Strong communication and customer‑facing skills.Ability to work with delivery teams, architects, and customers.Good documentation skills (HLD/LLD, runbooks).Problem-solving skills and ownership mindset.
  • Strong communication and customer‑facing skills.
  • Ability to work with delivery teams, architects, and customers.
  • Good documentation skills (HLD/LLD, runbooks).
  • Problem-solving skills and ownership mindset.
L2 Security Implementation Engineer — Careers | Saints & Masters