Bestkaam Logo
People Prime Worldwide Logo

Microsoft Sentinel Content Developer

Chennai, Tamil Nadu, India

1 month ago

Applicants: 0

Salary Not Disclosed

N/A

Job Description

About company: They balance innovation with an open, friendly culture and the backing of a long-established parent company, known for its ethical reputation. We guide customers from what?s now to what?s next by unlocking the value of their data and applications to solve their digital challenges, achieving outcomes that benefit both business and society. ? Job Title: Microsoft Sentinel Content Developer ? Location: Bengaluru, Chennai, Pune, Hyderabad or Coimbatore ? Experience: 4-12 yrs ? Notice Period:- Immediate joiners. JD: Key Responsibilities: Log Parsing & Normalization: Perform parsing and normalization of logs at the Datadog observability pipeline level. Create and manage Data Collection Rules (DCRs) in Microsoft Sentinel with custom parsing and transformation logic. Map logs to Microsoft Sentinel Normalized Schema (ASIM) where applicable. Ensure high-quality, structured data ingestion for effective detection and investigation. Detection Rule Migration: Analyze and understand existing Splunk detection rules written in SPL. Translate and migrate detection logic into Microsoft Sentinel analytic rules using KQL. Optimize rules for performance, accuracy, and minimal false positives. Content Development: Develop and maintain custom analytic rules , hunting queries , and workbooks in Sentinel. Collaborate with threat detection teams to build use cases aligned with MITRE ATT&CK and other frameworks. Collaboration & Documentation: Work closely with SOC, engineering, and cloud teams to understand log sources and detection requirements. Document parsing logic, rule mappings, and enrichment strategies for operational transparency. Required Skills: Strong experience with Microsoft Sentinel , KQL , and Data Collection Rules (DCR) . Hands-on experience with Splunk SPL and detection rule development. Familiarity with Datadog log formats and observability pipelines. Understanding of ASIM schema , Microsoft Defender XDR , and Sentinel connectors. Experience with log enrichment , GeoIP , and custom field mapping . Ability to work independently and take ownership of content development tasks. Preferred Qualifications: Microsoft certifications (e.g., SC-200, AZ-500). Knowledge of threat detection frameworks (MITRE ATT&CK, CIS, etc.). Familiarity with CI/CD pipelines for Sentinel content deployment.

Additional Information

Company Name
People Prime Worldwide
Industry
N/A
Department
N/A
Role Category
Software Engineer
Job Role
Mid-Senior level
Education
No Restriction
Job Types
Remote
Gender
No Restriction
Notice Period
Less Than 30 Days
Year of Experience
1 - Any Yrs
Job Posted On
1 month ago
Application Ends
N/A

Similar Jobs

Emerson

1 month ago

AI/ML Developer

Emerson

Kyndryl India

4 weeks ago

Client Support Relations - Japanese Language Services

Kyndryl India

Trilogy

1 month ago

Senior Java Developer, Trilogy (Remote) - $60,000/year USD

Trilogy

H&M

1 month ago

Software Engineer - CDN

H&M

Bellurbis

1 month ago

Frontend Developer (ReactJS Developer)

Bellurbis

Ciena

1 month ago

Python/Golang Developer- Kubernetes

Ciena

Walmart Global Tech India

1 month ago

SOFTWARE ENGINEER III

Walmart Global Tech India

Coditas

1 month ago

Angular Developer

Coditas

Digivance Solutions

1 month ago

DevOps Engineer

Digivance Solutions

Accenture in India

1 month ago

Application Developer

Accenture in India