
The onsite Security Engineer shall:
Review Microsoft Sentinel log ingestion and monitoring coverage
Validate and tune detection use cases
Identify telemetry or ingestion gaps
Coordinate remediation with staff
Support vulnerability prioritization and patch governance validation
Validate log routing and normalization (including tools such as Cribl, where applicable)
Provide technical support during security events
The onsite resource must demonstrate proficiency with:
Microsoft Sentinel
Microsoft Defender for Endpoint (Windows and macOS)
Microsoft Defender for Identity
AWS log ingestion and cloud telemetry
Onsite support shall supplement, and not replace, required 24x7x365 remote monitoring services.
At a minimum one (1) certification listed below
CompTIA Security +
GIAC Certified Incident Handler (GCIH)
GIAC Security Expert (GSE)
GIAC Information Security Professional (GISP)
GIAC Security Leadership Certification (GSLC)
ISC2 Certified Authorization Professional (CAP)
ISC2 System Security Certified Practitioner (SSCP)
ISC2 Certified Information System Security Professional (CISSP)
Certified Information Systems Auditor (CISA)
ISACA Certified in Risk and Information System Control (CRISC)
Security Certified Program Security Certified Network Professional (SCNP)
Security Certified Program Security Certified Network Architect (SCNA)
Security Certified Network Professional (SCNP)
Security Certified Network Architect (SCNA)