Description
Job Summary:
Professional to lead digital transformation in cybersecurity, focusing on the evolution and modernization of SIEM and SOAR platforms with Microsoft Sentinel.
Key Highlights:
1. Experience in global projects and complex environments
2. Strong international exposure and high technical expertise
3. Opportunity for continuous learning and career growth
Job Description
At Avanade, we lead digital transformation through innovative solutions built on the Microsoft ecosystem.
This position is strategic for strengthening our clients’ cybersecurity capabilities, with a focus on the evolution, operation, and modernization of **SIEM and SOAR platforms using Microsoft Sentinel**.
The role involves global projects, complex environments, and high-impact challenges—directly contributing to modern, intelligent, scalable, and data-driven security operations, automation, and Artificial Intelligence, supporting decision-making and protecting clients’ businesses.
By joining Avanade, you will have the opportunity to work on impactful projects with strong international exposure, high technical standards, and close involvement in strategic security decisions. Here, we value continuous learning, innovation, collaboration, and career growth within an inclusive and diverse environment. **Together we do what matters.**
**Learn more about some of our benefits:**
* Meal or food allowance
* Multibenefit Card (up to Senior Consultant)
* Health and dental insurance
* Certifications and training
* Life insurance
* Private pension plan
* Avababy: Pregnancy support and welcome kit for new parents
* Company profit-sharing program
* Wellhub
* Childcare assistance
* Career mentoring
* Birthday Off policy
* Well-being sessions
* For managerial roles: Corporate vehicle, parking, and fuel allowance
**Responsibilities**
* Design, implement, and evolve **SIEM and SOAR solutions focused on Microsoft Sentinel**, ensuring operational efficiency, automation, and scalability.
* Define and evolve **security architectures for cloud and hybrid environments**, aligned with business needs and industry best practices.
* Lead initiatives in **security-focused data engineering**, including log onboarding, ingestion, normalization, parsing, and enrichment of large-scale log volumes.
* Develop and optimize **detection content**, including analytics rules, advanced KQL queries, executive dashboards, and operational workbooks in Sentinel.
* Develop and implement **incident response playbooks and SOAR automations** using Azure Logic Apps and native Sentinel integrations.
* Integrate and operationalize **Threat Intelligence sources**, including TIPs, STIX/TAXII, OTX, OSINT, and YARA-based rules.
* Apply frameworks such as **MITRE ATT\&CK, Cyber Kill Chain, and NIST**, translating concepts into practical detection and response use cases.
* Leverage **Artificial Intelligence applied to cybersecurity**, including Microsoft Security Copilot, to accelerate investigations, correlations, and insight generation.
* Conduct **cybersecurity maturity assessments**, identifying risks, gaps, and opportunities for improvement.
* Support the definition of **strategic cybersecurity roadmaps**, aligning technical requirements with clients’ business objectives.
* Serve as a technical reference in projects and workshops, communicating recommendations clearly, structurally, and value-oriented to both technical and executive audiences.
Qualifications
**Skills and Experience**
* Solid experience as a **Cybersecurity Consultant**, with significant involvement in **Microsoft Sentinel** as the primary SIEM platform.
* Experience in complex, distributed, large-scale corporate environments with multiple log sources and integrations.
* Experience developing **detections, automations, and integrations** using KQL, Logic Apps, Functions, and Azure data services.
* Knowledge of **Azure and identity security**, including Microsoft Entra ID, Defender XDR, Defender for Cloud, Azure Policy, and architectures based on CAF and ALZ.
* Experience with **maturity assessments, solution design, and security governance**.
* Interest or hands-on experience in **AI applied to modern SOCs and security automation**.
* **Advanced English (minimum C1\)** for working in global environments and engaging with international stakeholders.
**Desired Technical Knowledge**
* **Microsoft Sentinel and associated ecosystem:**
+ Azure Log Analytics
+ Azure Data Explorer (ADX)
+ Azure Data Lake
+ Azure Event Hubs
+ Data Collection Endpoints (DCE) and Data Collection Rules (DCR)
+ Azure Logic Apps and Azure Functions
+ Microsoft Defender XDR
+ Microsoft Security Copilot (preferred)
* **DevOps and security automation (preferred):**
+ Infrastructure as Code (ARM, Bicep, Terraform)
+ Azure DevOps and GitHub (Actions, Repos, Advanced Security)
+ CI/CD integrations for security and data workloads
+ SecDevOps / DevSecOps practices
* **Other relevant experience (preferred):**
+ Splunk, IBM QRadar, or Google Security Operations
+ Security architecture and endpoint management
AI solutions applied to cybersecurity
+
**Desired Certifications:**
* SC\-200 – Security Operations Analyst
* SC\-100 – Cybersecurity Architect
* AZ\-500 – Azure Security Engineer
SC\-300 – Identity and Access Administrator
*
**Market Certifications (additional preferences):**
* CISSP • CCSP
* CompTIA Security\+ • CySA\+
* GIAC / SANS (GSEC, GCIH, GCIA, GCED)
* Cloud Security certifications (AWS or Google)