Job Description
Job Title:  Microsoft Sentinel Platform Engineer
City:  Pune
State/Province:  Maharashtra
Posting Start Date:  3/17/26
Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest ambitions and build future-ready, sustainable businesses. With over 230,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.
Job Description: 

Job Description

The Sentinel Platform Engineer – L3 is the highest-tier technical expert responsible for end-to-end engineering, optimization, and advanced troubleshooting of the Microsoft Sentinel platform within the SOC. This role ensures platform reliability, architecture governance, seamless data ingestion, analytics development, automation, threat detection maturity, and integration with enterprise security controls.
The L3 engineer also acts as the primary escalation point for complex incidents and provides guidance to L1/L2 SOC teams.

͏

Key Responsibilities

1. Sentinel Platform Ownership & Architecture

  • Own full lifecycle management of Microsoft Sentinel, including architecture design, scaling, performance optimization, and maintenance.
  • Define and enforce Sentinel platform governance, naming standards, and RBAC policies.
  • Design and enhance Log Analytics workspace architecture, data retention policies, and workspace linking.
  • Ensure high availability, cost optimization, and platform resilience.

2. Data Connectors & Ingestion Engineering

  • Onboard, configure, and troubleshoot Sentinel data connectors (Syslog, CEF, AMA, custom connectors, API integrations).
  • Build and manage scalable data ingestion pipelines for security logs from telco, cloud, network, and core systems.
  • Optimize ingestion costs, data normalization (ASIM), and data mapping.

3. Analytics Rules & Threat Detection Engineering

  • Develop and optimize KQL-based analytic rules for advanced threat detection.
  • Improve detection logic through threat hunting patterns, MITRE ATT&CK mapping, and false-positive reduction.
  • Perform periodic health checks on analytics rule performance and data coverage.

4. SOAR, Automation & Playbook Engineering

  • Build advanced Logic Apps and SOAR playbooks for automated response.
  • Integrate automation across security tools, ITSM, identity systems, and network controls.
  • Troubleshoot complex automation failures and enhance playbook efficiencies.

5. Advanced Troubleshooting & Escalation Support

  • Serve as final technical escalation point for Sentinel platform issues.
  • Analyze and resolve ingest failures, connector breakdowns, workspace anomalies, and rule malfunctions.
  • Support IR teams with deep-dive KQL investigations and platform-level forensics.

6. Monitoring, Health, and Performance Management

  • Continuously monitor Sentinel health, connector stability, ingestion latency, and automation performance.
  • Conduct regular platform audits and enforce configuration compliance.
  • Maintain dashboards for platform KPIs and operational maturity.

7. Documentation, Standards, and Best Practices

  • Create and maintain engineering runbooks, platform architecture diagrams, and standard operating procedures.
  • Mentor L1/L2 SOC analysts and provide technical knowledge sessions.
  • Participate in change management, risk assessments, and security architecture reviews.

 

͏

Required Skills & Experience

Technical Skills

  • Expert-level hands-on experience with Microsoft Sentinel (minimum 4–6 years).
  • Strong proficiency in KQL, including performance tuning and complex query building.
  • Deep understanding of:
    • Log Analytics Workspaces
    • Azure Monitor Agent (AMA)
    • Sentinel Analytics, Workbooks, Watchlists
    • Logic Apps / SOAR automation
    • REST API integration
    • ASIM & Schema Mapping
  • Knowledge of security frameworks: MITRE ATT&CK, NIST CSF, ISO 27001.
  • Experience with Windows, Linux, network logs, firewalls, proxies, identity systems (AD/AAD).
  • Strong debugging skills in ingestion issues, schema mismatches, parsing/normalization.
Mandatory Skills: Security Information Event Management .

 

Experience: 5-8 Years .

 

Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.
Information at a Glance

Get Job Alerts

Receive notifications when we have open roles and get other relevant career news


Register >
 

Join Us

Explore open roles that match your interests and skills


Search Jobs >
 

If you encounter any suspicious mail, advertisements, or persons who offer jobs at Wipro, please email us at helpdesk.recruitment@wipro.com. Do not email your resume to this ID as it is not monitored for resumes and career applications.

Any complaints or concerns regarding unethical/unfair hiring practices should be directed to our Ombuds Group at ombuds.person@wipro.com.

We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, caste, creed, religion, gender, marital status, age, ethnic and national origin, gender identity, gender expression, sexual orientation, political orientation, disability status, protected veteran status, or any other characteristic protected by law.

Wipro is committed to creating an accessible, supportive, and inclusive workplace. Reasonable accommodation will be provided to all applicants including persons with disabilities, throughout the recruitment and selection process. Accommodations must be communicated in advance of the application, where possible, and will be reviewed on an individual basis. Wipro provides equal opportunities to all and values diversity.