More jobs:
Cyber Security Engineer
Job in
Austin, Travis County, Texas, 78716, USA
Listed on 2026-01-04
Listing for:
AllSTEM Connections
Full Time
position Listed on 2026-01-04
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer
Job Description & How to Apply Below
Summary
The Microsoft Sentinel SOAR & UEBA Engineer is responsible for designing, developing, and maintaining advanced security automation, analytics, and behavioral detection capabilities within Microsoft Sentinel. This role focuses on SOAR playbook development, UEBA analytics engineering, SIEM content creation, and system integrations to improve threat detection, response efficiency, and overall security posture. The engineer works closely with cybersecurity leadership, SOC analysts, and cross-functional IT teams to deliver scalable, automated, and intelligence-driven security operations.
EssentialJob Functions (EJFs)
- Design, develop, test, and deploy Sentinel SOAR automation playbooks using Azure Logic Apps, Azure Functions, ARM templates, and REST APIs
. - Create automated workflows for alert enrichment, triage, response actions, notifications, and case management
. - Integrate Microsoft Sentinel with third-party security and enterprise systems (EDR, IAM, ticketing systems, email gateways, firewalls, etc.) to automate security operations.
- Develop custom UEBA detection rules
, anomaly models, ML-based behavior patterns, and advanced hunting queries using KQL
. - Build and maintain analytics rules, data parsers, normalization rules, and entity behavior profiles
. - Evaluate behavioral anomalies and collaborate with cybersecurity teams to fine-tune detection logic and reduce false positives
. - Design and implement custom data connectors, ingestion pipelines, and data transformation logic
. - Create and maintain dashboards, workbooks, hunting queries, and detection-as-code assets
. - Perform platform tuning to improve performance, signal-to-noise ratio
, and alignment with MITRE ATT&CK and Zero Trust principles
.
- Develop supporting scripts, microservices, helper APIs, and automation modules using Python, Power Shell, .NET, or similar languages
. - Work with CI/CD pipelines, Dev Ops practices, version control systems, and infrastructure-as-code where applicable.
- Create and maintain technical design documents, SOPs, architecture diagrams, and automation runbooks
. - Collaborate with DSHS, HHSC CISO Office
, and cross-functional stakeholders on requirements, testing, and deployment. - Provide Tier III engineering support for Sentinel-related issues and participate in after-action reviews as needed.
Knowledge of:
- Microsoft Sentinel architecture,
SOAR automation
, and UEBA capabilities
. - Azure cloud services including Logic Apps, Azure Functions, Event Hubs, Key Vault, and Azure AD
. - Security operations processes such as triage, threat detection, incident response, and threat modeling
. - MITRE ATT&CK, NIST CSF, and Zero Trust Architecture concepts.
- CI/CD pipelines, Dev Ops methodologies, and Git-based version control
. - API integrations and JSON/YAML data structures.
- Building Logic App workflows and custom Sentinel automation playbooks.
- Writing complex KQL queries for analytics, hunting, and behavioral detections.
- Developing custom data connectors, parsers, and data mappings
. - Designing, tuning, and optimizing UEBA detection models
. - Debugging SOAR workflows and resolving integration and automation issues
. - Communicating complex technical concepts to technical and non-technical stakeholders
.
- Mid-Senior level
- Contract
- Information Technology
- Government Relations Services
- Medical insurance
- Vision insurance
Referrals increase your chances of interviewing at AllSTEM Connections by 2x
#J-18808-LjbffrTo View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×