← Back to jobs

Stefanini IT Solutions Logo
Security Automation Engineer

Stefanini IT Solutions

 

Raritan, NJ, USA

Posted On: Just posted
Experience: 5+ years
Availability: Hybrid
Openings: 1
Category: Automation Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

Build and maintain automated security pipelines that integrate endpoint telemetry with SIEM platforms.

This role is on-site.

Responsibilities

  • Stand up and harden FDR to S3 delivery for Falcon Device Control events, ensuring schema normalization.
  • Configure Microsoft Sentinel ingestion for FDR data and AD/Entra ID events, developing KQL parsers and tables for correlation.
  • Author KQL analytics and rules joining Windows Event IDs (4728/4729/6416/4663) with CrowdStrike events to drive host policy changes.
  • Build idempotent automation using PowerShell, Python, or Logic Apps to call CrowdStrike APIs based on Sentinel signals, including audit logging.
  • Develop unit and integration tests for parsers and functions, and document full runbooks for operations.

Required Skills

  • 5+ years in security engineering or automation with SIEM (Microsoft Sentinel) and endpoint security integrations.
  • Proficiency in KQL, Python, and/or PowerShell.
  • Hands-on experience with REST/OAuth2 API integration.
  • Experience with CrowdStrike Falcon (preferably Device Control) and FDR pipelines.
  • Solid understanding of Windows Security Event Log semantics, specifically 4728/4729, 6416, and 4663.
  • Cloud data engineering basics, including AWS S3 object lifecycle and secured ingestion.
  • Experience with CI/CD practices for packaging automation artifacts.
  • Familiarity with Azure identity fundamentals and Entra ID group modeling.

Preferred Skills

  • Experience with Logic Apps and Azure Functions for automation workflows.

Education

Any Gradute

Related Jobs

No related jobs found

← Back to jobs