Bestkaam Logo
People Prime Worldwide Logo

Microsoft Sentinel Content Developer

Hyderabad, Telangana, India

1 month ago

Applicants: 0

Salary Not Disclosed

N/A

Job Description

Job Title: Microsoft Sentinel Content Developer Location: Bengaluru, Chennai, Pune, Hyderabad or Coimbatore Experience Level: 4?12 years Employment Type: Contract JOB TYPE : Hybrid JD : Role Overview: We are looking for a skilled and proactive Microsoft Sentinel Content Developer to support our SIEM transformation initiatives. The ideal candidate will have hands-on experience in log parsing, normalization, and detection rule development, with a strong understanding of both Splunk and Microsoft Sentinel environments. This role requires working closely with Datadog observability pipelines and Microsoft Sentinel to ensure seamless log ingestion and detection coverage. Key Responsibilities: Log Parsing & Normalization: Perform parsing and normalization of logs at the Datadog observability pipeline level. Create and manage Data Collection Rules (DCRs) in Microsoft Sentinel with custom parsing and transformation logic. Map logs to Microsoft Sentinel Normalized Schema (ASIM) where applicable. Ensure high-quality, structured data ingestion for effective detection and investigation. Detection Rule Migration: Analyze and understand existing Splunk detection rules written in SPL. Translate and migrate detection logic into Microsoft Sentinel analytic rules using KQL. Optimize rules for performance, accuracy, and minimal false positives. Content Development: Develop and maintain custom analytic rules , hunting queries , and workbooks in Sentinel. Collaborate with threat detection teams to build use cases aligned with MITRE ATT&CK and other frameworks. Collaboration & Documentation: Work closely with SOC, engineering, and cloud teams to understand log sources and detection requirements. Document parsing logic, rule mappings, and enrichment strategies for operational transparency. Required Skills: Strong experience with Microsoft Sentinel , KQL , and Data Collection Rules (DCR) . Hands-on experience with Splunk SPL and detection rule development. Familiarity with Datadog log formats and observability pipelines. Understanding of ASIM schema , Microsoft Defender XDR , and Sentinel connectors. Experience with log enrichment , GeoIP , and custom field mapping . Ability to work independently and take ownership of content development tasks. Preferred Qualifications: Microsoft certifications (e.g., SC-200, AZ-500). Knowledge of threat detection frameworks (MITRE ATT&CK, CIS, etc.). Familiarity with CI/CD pipelines for Sentinel content deployment.

Additional Information

Company Name
People Prime Worldwide
Industry
N/A
Department
N/A
Role Category
Data Analyst
Job Role
Mid-Senior level
Education
No Restriction
Job Types
Remote
Gender
No Restriction
Notice Period
Less Than 30 Days
Year of Experience
1 - Any Yrs
Job Posted On
1 month ago
Application Ends
N/A

Similar Jobs

TELUS Digital AI Data Solutions

1 month ago

Online Data Analyst

TELUS Digital AI Data Solutions

Eastvantage

1 month ago

Data Operations Analyst

Eastvantage

Excel, CSV, JSON +2
Clarivate

1 month ago

Senior Healthcare Research & Data Analyst

Clarivate

BlackRock

1 month ago

Analyst, MDM Operations

BlackRock

Tata Consultancy Services

16 hours ago

Dot Net Fullstack + Angular Developer

Tata Consultancy Services

Process Point Technologies Corporation

4 weeks ago

Application Developer

Process Point Technologies Corporation

Conviva

1 month ago

Sr. IT Specialist

Conviva

GEDU Services

4 weeks ago

Business Analyst

GEDU Services

TeamUpdraft

1 month ago

Lead Developer (all-in-one-security) - WordPress

TeamUpdraft

Accenture in India

1 day ago

Delivery Operations Senior Analyst

Accenture in India