Cybersecurity Consultant - MDR (Managed Detection and Response) & Sentine;
NTT DATA Romania SA Brașov, Romania
IT Services and IT Consulting · 10,001+ employees
About the role
You will act as a trusted advisor to clients, designing and optimizing Microsoft Sentinel environments while developing advanced threat detection rules and automation playbooks. Additionally, you will lead threat hunting activities and collaborate with cross-functional teams to ensure robust incident response and security posture improvements.
What they look for
Requirements
Candidates must have 5-7 years of experience in cybersecurity, specifically with Microsoft Sentinel, KQL, and cloud security architectures. A bachelor's degree in a relevant field is required, along with strong communication skills and the ability to participate in a 24x7 on-call rotation.
Full description
Who we are
NTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.
Our mission is to protect and empower organizations through cutting-edge Managed Detection and Response (MDR) solutions, deep technical expertise, and a client-first mindset.
We are seeking an experienced Cybersecurity professional with strong expertise in Microsoft Sentinel, security operations, threat detection, and cloud security, who can combine hands-on engineering capabilities with a trusted advisor approach towards our customers.
What you'll be doing
- Build strong, meaningful “trusted advisor” relationships with clients on behalf of NTT DATA and act as the main Cybersecurity Advisor for one or more customers.
- Design, implement, maintain, and optimize Microsoft Sentinel environments, ensuring proper configuration, data ingestion quality, and alignment with customer security objectives.
- Develop, refine, and optimize detection rules, analytics, workbooks, dashboards, and advanced KQL queries for threat detection, hunting, investigation, and reporting.
- Build and maintain SOAR playbooks using Logic Apps to automate triage, response actions, and security workflows.
- Support customers in optimizing the detection, response, mitigation, and reporting of cybersecurity threats within their environments.
- Lead and support threat hunting activities using Microsoft Sentinel, Microsoft Defender XDR, and relevant Threat Intelligence sources.
- Oversee the onboarding and integration of new log sources, ensuring appropriate mapping, normalization, governance, and data quality.
- Continuously tune alerts, analytics rules, data connectors, and detection logic to improve accuracy and reduce the signal-to-noise ratio.
- Provide expertise across Network/Perimeter/Cloud Security, SecOps, Threat Intelligence, EDR, and detection capabilities.
- Analyze network traffic and security telemetry and design relevant detection use cases based on identified risks and attack patterns.
- Propose recommendations for improving customers' cybersecurity posture and reducing identified risks.
- Design and improve cybersecurity processes, procedures, runbooks, response workflows, and training programs aligned with organizational risk and industry standards.
- Produce comprehensive technical documentation, including use cases, detection logic, response procedures, runbooks, and architectural diagrams.
- Collaborate with SOC analysts, security engineers, cloud teams, application owners, and customer stakeholders to ensure coordinated incident response and remediation activities.
- Act as a Subject Matter Expert (SME) in Cybersecurity and MDR solutions, providing technical guidance and mentorship to junior team members and cross-functional teams.
- Stay up to date with emerging cybersecurity threats, technologies, attack techniques, and industry trends and translate them into improvements to detection and response capabilities.
- Participate in an on-call rotation where required.
What you'll bring along
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field.
- Minimum 5-7 years of professional experience in IT Cybersecurity, Security Operations, Detection Engineering, MDR, or a similar role.
- Extensive hands-on experience administering and engineering Microsoft Sentinel solutions, including analytics rules, automation, log management, and data connectors.
- Strong proficiency in KQL, with the ability to develop complex queries for threat detection, investigation, hunting, and reporting.
- Strong knowledge of SIEM, SOAR, EDR, firewalls, IDS/IPS, and other security technologies.
- Practical experience with Microsoft Defender XDR solutions, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.
- Very good knowledge of Azure and cloud security concepts, including identity management, network security controls, and cloud-native security architecture.
- Technical understanding of common Microsoft environments and technologies such as Entra ID, Microsoft 365, Active Directory, and Exchange.
- Deep understanding of security monitoring, threat detection methodologies, incident response, threat hunting, and SOC operations.
- Strong understanding of log source onboarding, normalization, and integration within Microsoft Sentinel.
- Understanding of cybersecurity domains such as network security, endpoint security, anomaly detection, Threat Intelligence, and cloud security.
- Good knowledge of the MITRE ATT&CK Framework and its application to detection engineering and threat hunting.
- Ability to perform network traffic analysis and translate findings into relevant detection and monitoring use cases.
- Experience integrating Microsoft Sentinel with third-party log sources, security tools, and other SIEM platforms such as Palo Alto XSIAM or Splunk is an advantage.
- Knowledge of scripting and automation technologies such as Python, Bash, PowerShell, Logic Apps, Ansible, or Terraform.
- Linux proficiency.
- Knowledge of security models, industry best practices, and generally accepted information security principles.
- Strong communication, stakeholder management, and documentation skills, with the ability to translate complex technical concepts into clear and actionable recommendations.
- Ability to work effectively in a customer-facing environment and communicate with both technical and non-technical stakeholders.
- Relevant certifications such as SC-200, SC-100, AZ-500, CISSP, CISM, SANS GCDA, SANS GCED, or other GIAC certifications are highly desirable.
- Ability and willingness to travel domestically and internationally when required.
- Availability for 24x7 on-call rotation.
- Proficiency in English is mandatory; German language skills are an advantage.
Similar roles
-
Director Cybersecurity Operational Risk Oversight
Citizens Bank Johnston, Rhode Island, United States · $178K–$220K/yr
-
Senior Security Engineer, Detection & Response
Aircall.io, Inc. San Francisco, California, United States · $180K–$220K/yr
-
Senior Security Engineer (m/w/d)
Yoummday GmbH Munich, Bavaria, Germany
-
Senior Security Engineer, Cloud and Infrastructure Security
Weight Watchers United States · $210K–$225K/yr
-
Staff Security Engineer - AI Security
Qube Research & Technologies London, England, United Kingdom
-
Cybersecurity Engineer - CBO
INNOVIM United States · $90K–$107K/yr