Cybersecurity Consultant

IBM • Bucharest, RO

Company

IBM

Location

Bucharest, RO

Type

Full Time

Job Description

Introduction

The Sentinel Content Engineer is responsible for designing implementing tuning and maintaining Microsoft Sentinel content to enable effective detection response and automation within the Client Security Operations Center (CSOC). This role ensures that Sentinel provides high-fidelity detections automated response capabilities and actionable dashboards aligned with the threat landscape and client requirements. The engineer works closely with SOC analysts (L1/L2) threat intelligence teams and client stakeholders to develop and continuously improve security use cases analytics rules and playbooks.

In this role you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers) where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. Our delivery centers offer our clients locally based skills and technical expertise to drive innovation and adoption of new technology.

Your role and responsibilities
Key Responsibilities / Tasks
Detection Engineering
  • Develop and maintain Sentinel analytics rules using KQL (Kusto Query Language).
  • Translate client requirements and threat intelligence into detection use cases.
  • Tune existing rules to reduce false positives while maintaining coverage.
  • Map detections to MITRE ATT&CK framework for coverage reporting.
SOAR Automation & Playbooks
  • Design implement and maintain Logic Apps playbooks for automated response and enrichment.
  • Integrate playbooks with external systems (ticketing platforms TI feeds EDR proxy MISP etc.).
  • Work with analysts to automate repetitive tasks (e.g. enrichment notification containment actions).
Content Lifecycle Management
  • Establish and follow a content development lifecycle (design test deploy maintain).
  • Maintain proper version control documentation and rollback procedures.
  • Regularly review and update detection and automation based on lessons learned from incidents.
Data Integration & Normalization
  • Onboard log sources into Sentinel (Azure Microsoft 365 EDR firewall proxy custom apps).
  • Ensure data connectors and normalization follow Sentinel’s schema (ASIM).
  • Work with client infrastructure teams to resolve ingestion issues and data gaps.
Dashboards & Reporting
  • Create Sentinel workbooks and dashboards for operational monitoring and executive reporting.
  • Provide SOC metrics KPIs and threat visibility dashboards for clients and leadership.
Collaboration & Continuous Improvement
  • Work with SOC L2/L3 analysts to refine detection and response workflows.
  • Incorporate threat intelligence feeds and client-specific IoCs into Sentinel content.
  • Proactively identify gaps in monitoring coverage and propose improvements.
  • Support security incident investigations by providing query expertise and custom rules.
Required education
Bachelor's Degree
Required technical and professional expertise
  • Microsoft Sentinel Expertise
    • Strong hands-on experience with Microsoft Sentinel (SIEM + SOAR).
    • Proficiency in KQL (Kusto Query Language) for writing and optimizing queries.
    • Experience with Logic Apps for playbook creation and orchestration.
    • Familiarity with Microsoft security stack (Defender EOP Azure Security Center).
  • Detection & Response Engineering
    • Ability to translate threat intelligence and MITRE ATT&CK techniques into detection logic.
    • Experience tuning detections to balance coverage and noise reduction.
    • Knowledge of incident response workflows and SOC operations.
  • Automation & Scripting
    • Proficiency with PowerShell Python or other scripting languages for automation.
    • Experience with API integrations (REST Graph API).
  • Log Management & Data Analysis
    • Understanding of common log sources (Windows Event Logs network devices cloud services).
    • Experience with log normalization parsing and schema mapping (ASIM).
  • Soft Skills & Behavioral Competencies
    • Strong problem-solving and analytical mindset.
    • Ability to communicate complex technical concepts to analysts and stakeholders.
    • Proactive in identifying improvements and proposing new detection/automation content.
    • High attention to detail with commitment to documentation and knowledge sharing.
Preferred Professional and Technical Expertise
  • Bachelor’s degree in Cybersecurity Computer Science or equivalent experience.
  • 3–5 years of experience in SOC SIEM engineering or security content development.
  • Microsoft Security certifications preferred:
    • SC-200 (Microsoft Security Operations Analyst)
    • SC-100 (Microsoft Cybersecurity Architect)
    • AZ-500 (Azure Security Engineer Associate)
  • Other security certifications a plus (GCIA GCTI Splunk Certified etc.).
Preferred technical and professional experience

Hiring manager and Recruiter should collaborate to create the relevant verbiage.

Apply Now

Date Posted

12/09/2025

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.2

Similar Jobs

Security Consultant - IBM

Views in the last 30 days - 0

The Sentinel Content Engineer role involves designing implementing and maintaining Microsoft Sentinel content for effective detection response and aut...

View Details

Security Consultant - IBM

Views in the last 30 days - 0

This job description outlines a security role requiring expertise in vulnerability management compliance and SIEM tools with certifications like CompT...

View Details

WebSphere Application Server (WAS) Admin - IBM

Views in the last 30 days - 0

The text describes an IBM job role requiring expertise in WebSphere and HTTP Server administration emphasizing technical skills and innovation in clie...

View Details

VPC Backend Team Lead (Java) - IBM

Views in the last 30 days - 0

This text describes a Software Developer role at IBM Consulting emphasizing collaboration with global clients innovation in hybrid cloud and AI soluti...

View Details

SWIFT Products Technical Specialist with PayPlus & IGTPlus - IBM

Views in the last 30 days - 0

This job description outlines a SWIFT Products Technical Specialist role at IBM requiring expertise in banking payment domains SWIFT technologies and ...

View Details

Integration Java Developer - IBM

Views in the last 30 days - 0

This job posting seeks an API Developer for the CBS Integration team in Bucharest requiring expertise in Java API development and integration technolo...

View Details