Siem Security Engineer

Merck Sharp & Dohme Corp

Not specified; not specified; competitive salary +...
Hybrid
Microsoft sentinel platform experience
Kusto query language (kql) proficiency
Cribl log routing and enrichment
Merck Sharp & Dohme Corp is seeking a SIEM Security Engineer to enhance their Microsoft Sentinel platform, focusing on log ingestion, detection engineering, and platform optimization within a hybrid work environment. The ideal candidate should have advanced proficiency in Kusto Query Language (KQL) and experience with Azure Data Explorer and Cribl for managing security telemetry

Job Summary

  • This role is responsible for taking ownership of the Microsoft Sentinel platform to enable scalable security monitoring and high-fidelity detections across a complex enterprise environment.
  • The engineer will design and maintain log ingestion pipelines using Cribl to ensure data quality, normalization, and cost optimization before ingestion into Sentinel or ADX.
  • Candidates must possess strong hands-on experience with KQL for analytics and hunting while collaborating with global SOC teams to reduce false positives and improve signal-to-noise ratios.

Matching Summary

Match Score: 85

Merck Sharp & Dohme Corp is seeking a SIEM Security Engineer to enhance their Microsoft Sentinel platform, focusing on log ingestion, detection engineering, and platform optimization within a hybrid work environment. The ideal candidate should have advanced proficiency in Kusto Query Language (KQL) and experience with Azure Data Explorer and Cribl for managing security telemetry.

Salary

Not specified; Not specified; Competitive salary and benefits package mentioned

Skills & Requirements

Must-have

  • Microsoft Sentinel platform experience
  • Kusto Query Language (KQL) proficiency
  • Cribl log routing and enrichment
  • Azure Data Explorer (ADX) usage
  • SOC incident response support
  • ITIL service management processes

Nice-to-have

  • Sentinel SOAR Logic Apps automation
  • MITRE ATT&CK aligned detection engineering
  • Python or PowerShell scripting skills
  • Zero-trust security architecture knowledge
  • Regulated enterprise environment experience
  • Global team collaboration capabilities

Key Requirements

  • Strong hands-on experience with Microsoft Sentinel
  • Advanced proficiency in Kusto Query Language (KQL)
  • Practical experience with Cribl for log management
  • Experience working with Azure Data Explorer (ADX)
  • Solid understanding of security logging and telemetry
  • Familiarity with ITIL processes and ServiceNow/Jira

Work Rights

Not specified

Tailored Resume

Cover Letter