This job is no longer available
This job expired on 21/09/2026. It no longer accepts applications.
Delivery Engineer – Microsoft Sentinel (SIEM/SOAR)
Noventiq GCC · Manama
Job description
About the role
We are seeking a hands‑on Delivery Engineer with deep expertise in Microsoft Sentinel (SIEM/SOAR) to design, implement and manage our security monitoring and response platform across Azure and Microsoft 365 environments.
Key responsibilities
- Design, deploy and administer Microsoft Sentinel, including data connectors, Log Analytics workspaces, Data Collection Rules and log ingestion.
- Develop and optimise analytics rules, hunting queries, workbooks, dashboards and reports using Kusto Query Language (KQL).
- Create and maintain SOAR playbooks with Azure Logic Apps, Automation Rules and Azure Functions.
- Integrate Sentinel with Microsoft security services (Defender XDR suite) and a wide range of third‑party security products.
- Perform threat hunting, incident investigation and response, reducing false positives and expanding detection coverage.
- Configure ASIM normalisation, custom parsers, Syslog, CEF, Windows Events, REST API connectors and AMA agents.
- Manage RBAC, data retention policies and cost optimisation for Sentinel.
- Document technical designs, runbooks and operational reports.
Required profile
- 3–8 years of experience in Security Operations or Security Engineering.
- Minimum 2 years of hands‑on Microsoft Sentinel implementation and administration.
- Strong background in SIEM engineering, SOAR automation, detection engineering, threat hunting and incident response.
Required skills
- Microsoft Sentinel (SIEM/SOAR)
- Kusto Query Language (KQL)
- Azure Logic Apps, Automation Rules, Azure Functions
- Azure RBAC and least‑privilege access management
- Microsoft Defender XDR suite (Endpoint, Identity, Office 365, Cloud Apps, Cloud)
- ASIM normalisation, Content Hub solutions, custom parsers
- Integration with Palo Alto Networks, Fortinet, Cisco Secure Firewall/ISE, Check Point, CrowdStrike Falcon, Zscaler (ZIA/ZPA), Proofpoint, F5 BIG‑IP
- Log ingestion via Syslog, CEF, Windows Events, REST APIs, AMA Agent
- Experience with AWS, GCP, IDS/IPS, VPN logs
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Bahrain.
Salaries by job title
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Noventiq GCC
Manama