freehire launches on Product Hunt on 26 August.

Follow →

SIEM/SOAR Security Engineer – Microsoft Sentinel & Defender

Summary

Design and implement threat detection rules in Microsoft Sentinel and Defender for Endpoint using KQL, integrate logs via parsers, and maintain security monitoring with Azure DevOps.

HCLTech is a global technology company, home to more than 227,000 people across 60 countries, delivering industry-leading capabilities centered around AI, digital, engineering, cloud and software, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology & Services, Semiconductor, Telecom and Media, Retail and CPG, Mobility and Public Services. Consolidated revenues as of 12 months ending March 2026 totaled $14.7B.

To learn how we can supercharge progress for you, visit .

Overview of the Role

As a SIEM/SOAR Security Engineer specializing in Microsoft Sentinel and Defender for Endpoint, you will play a pivotal role in enhancing Achmea’s security posture following its migration to Azure-based solutions. Your mission is to collaborate with cross-functional security teams to develop, implement, and refine advanced threat detection capabilities. This role directly contributes to safeguarding organizational assets and streamlining security operations, ensuring alignment with HCLTech’s commitment to delivering robust, cutting-edge cybersecurity solutions.

Detailed Responsibilities

  • Design, develop, and implement new detections and abuse cases within Microsoft Sentinel and Defender for Endpoint using Kusto Query Language (KQL).

  • Collaborate with IT Security teams to build and optimize SIEM content and security monitoring capabilities.

  • Develop scripts (parsers) to interpret log data and integrate it into the SIEM environment.

  • Utilize CI/CD pipelines and Azure DevOps to facilitate efficient deployment and maintenance of security solutions.

  • Provide technical expertise in Microsoft365 security toolsets, ensuring comprehensive protection across platforms.

  • Support vulnerability management and contribute to the development of security monitoring solutions.

  • Participate in the functional management of IT4Security tooling and maintain operational excellence.

  • Document and communicate technical findings and recommendations clearly in English, both verbally and in writing.

  • Work as part of the SIEM Build team within the Security Scanning & Engineering (SS&E) department, actively contributing to team objectives.

Skill Requirements

  • University/HBO-level education or equivalent experience in IT Security.

  • Proven proficiency in Kusto Query Language (KQL), with hands-on experience in Microsoft Sentinel and Microsoft Defender for Endpoint.

  • Strong understanding of Microsoft365 security toolsets, Azure DevOps, and CI/CD processes.

  • Relevant certifications in Microsoft technologies, particularly Azure and security-related domains.

  • Experience with scripting languages such as PowerShell or Python, including parser development for log interpretation.

  • Excellent English communication skills, both written and spoken.

Other Requirements (Optional)

  • Advanced knowledge of Microsoft Defender for Endpoint is highly advantageous.

  • Experience working in multinational, collaborative environments.

  • Familiarity with IT4Security tooling and advanced vulnerability management practices.

Career Development Opportunities

  • At HCLTech, we are committed to nurturing your professional growth through structured training programs, certification sponsorships, and access to cutting-edge technologies. Opportunities for advancement include leadership roles within security engineering, specialization in advanced cloud security, and cross-functional movement into broader IT architecture. Our global network and dedication to continuous learning empower you to shape your career path, contribute to impactful projects, and become a recognized expert in the cybersecurity domain.

This is a hybrid position from Warsaw location.

Benefit package:

  • Life insurance

  • Private medical care

  • MultiSport Card

  • Subsidy for glasses

  • Subsidy to language courses

  • Christmas and holiday bonuses

See also