Tóm lược
Mô tả công việc
Tóm tắt công việc
About the Role:
We are looking for a highly skilled Senior Engineer to lead and elevate our SIEM & Security Automation capabilities across the Group. In this role, you will be the technical owner of our Microsoft Sentinel platform—designing, engineering, and optimizing advanced detection use cases and automated response workflows that strengthen our cyber defence posture.
Requirements:
As an SIEM & Security Automation (Microsoft Sentinel), you will be responsible for the following tasks:
- Lead the administration, configuration, and optimization of the Group’s SIEM/SOAR platforms, with a primary focus on Microsoft Sentinel.
- Design, build, and maintain advanced analytics rules, UEBA use cases, hunting queries (KQL), workbooks, playbooks, and automations within Sentinel.
- Develop, customize, and maintain Logic Apps, Azure Functions, and other automation workflows to enhance detection, response, and remediation capabilities.
- Drive the continuous improvement of detection engineering practices, ensuring high-fidelity alerts and reduced false positives.
- Oversee the end-to-end lifecycle of security incident response automation, including design, testing, deployment, and documentation.
- Collaborate closely with Security Operations, Cloud, Infrastructure, and Application teams to ensure seamless integration of data sources and automation workflows.
- Evaluate new Sentinel features, Azure security capabilities, and emerging SOAR technologies to recommend enhancements aligned with Group Information Security strategies.
- Lead or support SIEM/SOAR transformation initiatives across Business Units to ensure consistent deployment, standards, and operational excellence.
- Establish and maintain coding standards, reusable components, and development best practices for security automation.
- Provide guidance, mentorship, and technical oversight to junior engineers and project teams.
- Attractive salary and benefits
- Hybrid working mode
- Full salary in probation & 13th month salary
- Social insurance on full salary from probation
- Extensive leave up to 18 days per year
- Annual health check
Yêu cầu công việc
- Minimum 4–8 years of experience in Security Operations, SIEM Engineering, SOAR Engineering, or Cloud Security Engineering roles.
- Strong hands-on experience with Microsoft Sentinel, including KQL query development, analytics rule tuning, data connector integration, and custom workbook creation.
- Proficient in Logic Apps development, including API connections, custom connectors, modular design, and workflow orchestration.
- Solid programming experience in languages such as:
- PowerShell
- Python
- or other scripting languages used for automation and Azure integrations.
- Deep understanding of SIEM architecture, log ingestion pipelines, parsing/normalization, and security telemetry design.
- Strong knowledge of Azure cloud services, including Azure Monitor, Azure Functions, Event Hub, Log Analytics, Azure AD/Entra ID, and security-related services.
- Demonstrated experience developing security automation playbooks and orchestrating incident response workflows.
- Excellent analytical, problem-solving, and stakeholder communication skills.
- Proven ability to lead complex detection engineering or SOAR automation projects.
- Certifications such as Microsoft Cybersecurity Architect (SC-100), Azure Security Engineer (AZ-500), Microsoft Sentinel (SC-200), or CISSP are highly advantageous.
Ngôn ngữ
-
English
Nói: Intermediate - Đọc: Intermediate - Viết: Intermediate
Yêu cầu kỹ thuật
- Cyber Security
- SIEM
- SOAR
- PowerShell
- Python
- API
- SQL Function
- Architecture
- MS Azure
- Logic Apps
- Azure AD
- CISSP
- Azure Monitor
- Azure Functions
- EventHub
- Sentinel
NĂNG LỰC
- Analytic Skills
- Problem Solving Skills
- Communication Skills
Thông tin doanh nghiệp
FWD VTC is making insurance simpler for everyone.
FWD Vietnam Technology Company Limited., known as FWD VTC, was set up in 2024 and is part of FWD Group. FWD VTC in Vietnam is one of FWD Group’s office locations serving multiple markets within the Group and employs team members in various functions including Group Technology and Operations, Group Digital & Data and our Centre of Excellence comprising cloud & infrastructure, information security, enterprise architecture and solution delivery.