The primary responsibilities of the Security Infrastructure Engineer Sentinel:
Functional Responsibilities:
Data Ingestion and Normalization Pipeline Management: Architect and maintain the ingestion of telemetry from multi-cloud (GCP, AWS, Azure) and on-premises environments using Bind Plane Forwarders, Cloud-to-Cloud (C2C) connectors, and Webhooks.
Parser Development: Design, build, and troubleshoot custom parsers (CBN) to ensure non-standard log sources are correctly normalized into the Unified Data Model (UDM).
Data Health Monitoring: Build dashboards to monitor ingestion rates, latency, and data drops to ensure the SIEM is always receiving high-quality, actionable data.
SOAR & Automation Engineering
Playbook Development: Design and code automated incident response playbooks in Sentinel SOAR using Python and visual builders.
Connector Engineering: Build and maintain API integrations between Sentinel SOAR and third-party tools (Firewalls, EDR, IAM, Ticketing systems).
Workflow Optimization: Automate repetitive manual tasks such as artifact enrichment, evidence gathering, and initial containment actions.
Case Management Configuration: Tailoring the SOAR environment to fit the SOC s operational needs, including custom fields, stages, and SLA tracking.
Platform Administration and Optimization
System Health Monitoring: Monitoring the ingestion health to ensure no data is dropped and that latency stays within acceptable limits.
Access Control: Managing Role-Based Access Control (RBAC) to ensure analysts have the correct level of access to sensitive data.
Threat Intel Ingestion: Managing the integration of Mandiant, Virus Total, and other third-party threat intelligence feeds to ensure detections are always up to date with the latest global threats.
Collaboration with SOC Team
Feedback Loops: Collaborating with Tier 1 and Tier 2 analysts to tune YARA-L rules based on real-world alert performance and noise levels.
Requirements Gathering: Interviewing incident responders to understand their manual workflows, then translating those into Sentinel SOAR playbooks.
Training & Enablement: Conducting knowledge transfer sessions on how to use UDM Search and the MS Sentinel interface to speed up investigations.
Alignment with Infrastructure Team
Data Ingestion Strategy: Working with GCP/AWS/Azure Architects to ensure that Cloud Logging and Pub/Sub are configured correctly for seamless export to Google SecOps platform.
Agent Deployment: Coordinating with IT Infrastructure teams to deploy and maintain Bind Plane Forwarders on on-premises servers and virtual machines.
Troubleshooting: Collaborating with Network Engineers to resolve connectivity issues or firewall blocks that prevent telemetry from reaching the Google SecOps platform.
Desired Candidate Profile
Academic & Professional Qualifications:
Bachelor s degree in computer science, IT, Cybersecurity, or equivalent.
SIEM Certification (Azure Sentinel).
Preferred: Security certifications such as Security+, CySA+, CEH, CISSP, GCIH
Sentinel Engineer Experience:
3 5 years of hands-on experience in Security Engineering, SOC Automation, DevOps Engineer, Security Operations, or Infrastructure Security.
Skills and Requirements:
SIEM/SOAR Mastery: Proven experience architecting and managing enterprise-grade platforms (e.g., Splunk, Azure Sentinel, or QRadar), with at least 1 2 years specifically focused on Google SecOps (Chronicle).
Key Requirement: Required skills: Google SecOps.
Coding & Scripting: Professional experience using Python to automate security workflows or build custom API connectors.
Cloud Infrastructure: Hands-on experience managing security within Google Cloud Platform (GCP), including VPC service controls, IAM, and Cloud Logging.
Languages: Python (Advanced), SQL (BigQuery), YARA/YARA-L, and Bash.
Frameworks: MITRE ATT&CK, NIST Cybersecurity Framework.
Tools: Git (Version Control), Terraform (Infrastructure as Code), Docker/Kubernetes (Containerization).
Data Standards: Deep knowledge of JSON, Protobuf, and Regex for log parsing and normalization.
Soft Skills:
Strong analytical thinking and problem-solving capability.
Excellent communication skills, able to explain technical findings to non-technical stakeholders.
Ability to work independently, manage multiple priorities, and meet deadlines.
Attention to detail and a structured, documentation-driven mindset.
المسؤوليات الأساسية لمهندس بنية الأمن Sentinel:
المسؤوليات الوظيفية:
إدارة خط أنابيب الاستحواذ وتطبيع البيانات: تصميم وصيانة استحواذ بيانات القياس من بيئات سحابية متعددة (GCP، AWS، Azure) وعلى أنظمة في الموقع باستخدام محوّلات Bind Plane، ووصلات Cloud-to-Cloud (C2C)، وWebhooks.
تطوير المحللات: تصميم وبناء واستكشاف أخطاء المحللات المخصصة (CBN) لضمان أن مصادر السجلات غير القياسية مُطَبَّعة بشكل صحيح ضمن نموذج البيانات الموحد (UDM).
مراقبة صحة البيانات: بناء لوحات قيادة لمراقبة معدلات الاستحواذ والكمون وفقدان البيانات لضمان أن الـ SIEM يتلقى دومًا بيانات عالية الجودة وقابلة للإجراء.
الهندسة SOAR والأتمتة
تطوير Playbook: تصميم وبرمجة إجراءات استجابة الحوادث الآلية في Sentinel SOAR باستخدام Python ومنشئي بصرية.
هندسة الموصلات: بناء وصيانة تكاملات API بين Sentinel SOAR وأدوات الطرف الثالث (جدران الحماية، EDR، IAM، أنظمة التذاكر).
تحسين سير العمل: أتمتة المهام اليدوية المتكررة مثل إثراء الأدلة، وجمع الدلائل، وإجراءات الاحتواء الأولية.
تكوين إدارة الحالات: تخصيص بيئة SOAR لتلبية احتياجات تشغيل SOC، بما في ذلك الحقول المخصصة، والمراحل، وتتبع SLA.
إدارة المنصة وتحسينها
مراقبة صحة النظام: مراقبة صحة الاستحواذ لضمان عدم فقدان البيانات وبقاء الكمون ضمن الحدود المقبولة.
التحكم بالوصول: إدارة التحكم في الوصول بناءً على الأدوار (RBAC) لضمان تمكين المحللين من الوصول إلى البيانات الحساسة بالدرجة الصحيحة.
استيعاب مصادر التهديد: إدارة تكامل تغذيات معلومات التهديد من Mandiant وVirusTotal وغيرها من الأطراف الثالثة لضمان أن التهديدات مكتشفة ومحدثة باستمرار مع أحدث التهديدات العالمية.
التعاون مع فريق SOC
دوائر التغذية المرتدة: التعاون مع محللي Tier 1 وTier 2 لضبط قواعد YARA-L بناءً على أداء التنبيهات الواقعي ومستويات الضجيج.
جمع المتطلبات: مقابلة المستجيبين للحوادث لفهم سير العمل اليدوي ثم تحويلها إلى Playbooks في Sentinel SOAR.
التدريب والتفعيل: عقد جلسات نقل المعرفة حول كيفية استخدام UDM Search وواجهة MS Sentinel لتسريع التحقيقات.
المواءمة مع فريق البنية التحتية
استراتيجية استنساخ البيانات: العمل مع معماريي GCP/AWS/Azure لضمان تكوين Cloud Logging وPub/Sub بشكل صحيح لصادرات سلسة إلى منصة Google SecOps.
نشر العوامل: التنسيق مع فرق بنية IT لنشر وصيانة محوّلات Bind Plane Forwarders على خوادم في الموقع وآلات افتراضية.
استكشاف الأخطاء: التعاون مع مهندسي الشبكات لحل مشاكل الاتصال أو حواجز الجدار الناري التي تمنع وصول القياس إلى منصة Google SecOps.
الملف المرغوب فيه للمرشح
المؤهلات الأكاديمية والمهنية:
درجة البكالوريوس في علوم الكمبيوتر أو تكنولوجيا المعلومات أو الأمن السيبراني، أو ما يعادلها.
شهادة SIEM (Azure Sentinel).
يفضَّل: شهادات الأمن مثل Security+، CySA+، CEH، CISSP، GCIH
خبرة مهندس Sentinel:
3–5 سنوات من الخبرة العملية في هندسة الأمن، أتمتة SOC، مهندس DevOps، عمليات الأمن، أو أمن البنية التحتية.
المهارات والمتطلبات:
إتقان SIEM/SOAR: خبرة مثبتة في تصميم وإدارة منصات من مستوى المؤسسة (مثلاً Splunk، Azure Sentinel، أو QRadar)، مع خبرة 1–2 سنوات تحديداً في Google SecOps (Chronicle).
المتطلب الأساسي: المهارات المطلوبة: Google SecOps.
البرمجة والسكربت: خبرة مهنية باستخدام Python لأتمتة سير عمل الأمان أو بناء موصلات API مخصصة.
البنية التحتية السحابية: خبرة عملية في إدارة الأمان ضمن Google Cloud Platform (GCP)، بما في ذلك ضوابط خدمات VPC وIAM وCloud Logging.
اللغات: Python (متقدم)، SQL (BigQuery)، YARA/YARA-L، وBash.
الأطر: MITRE ATT&CK، إطار NIST للأمن السيبراني.
الأدوات: Git (التحكم بالإصدارات)، Terraform (البنية كرمز)، Docker/Kubernetes (التعبئة)
معايير البيانات: معرفة عميقة بـ JSON، Protobuf، وRegex لتحليل وتطبيع السجلات.
المهارات الناعمة:
تفكير تحليلي قوي وقدرة على حل المشكلات.
مهارات تواصل ممتازة، القادرة على شرح النتائج التقنية لأصحاب المصلحة غير التقنيين.
القدرة على العمل بشكل مستقل، إدارة أولويات متعددة، والالتزام بمواعيد.
الانتباه إلى التفاصيل وتبني أسلوب منظم قائم على التوثيق.