EndCyber Security Engineer (Microsoft Security and Autpoint Management Engineer- Security Specialist
Date: Aug 10, 2026
Location: HU
Company: KUKA Group
Make an impact
- Strong understanding of log pipelines, schema mapping and telemetry quality
- Own and maintain the Microsoft Sentinel SIEM platform, including log source onboarding, data ingestion, normalization, and connector management, while ensuring optimal performance, reliability, and cost efficiency.
- Analyze log sources to ensure data quality, normalization and completeness
- Ability to analyze and interpret complex security data and trends and Skills in developing actionable insights from data patterns and anomalies
- Tool integration and relevant data on-bording
- Maintain technical documentation , architecture patterns and operational procedure and security standard
- Experience building security automation using Azure Logic Apps as part of the incident response (SIEM/XDR/SOAR).
- Monitoring ingestion costs, and optimizing retention policies to balance security needs with operational expenses.
- Proficiency in scripting languages like PowerShell and Python is required for automating tasks and developing custom integrations. You should understand Sentinel's automation and orchestration capabilities and know how to leverage them.
- Evaluate new Microsoft security features and contribute to security architecture standards and guidelines
- Design automated integrations for Threat Intelligence Platforms (TIP)
- Enable and operationalize Microsoft Defender AI capabilities across the security ecosystem. Extend detection coverage to the company's own AI, Copilot, custom AI applications, agent and non-human identities.
What you need to succeed
- Degree in Computer Science or a related technical degree, or strong IT
- Experience in Microsoft Sentinel and Defender
- Must be willing to work in major incident
- previous hands-on experience in the information security field
- Hands on experience with cyber security tools such as SIEM, XDR, SOAR, IDS/IPS, antivirus, endpoint protection, Microsoft Sentinel, Defender for endpoint, various open source solutions
- Supporting cyber engineering and operational security initiatives across infrastructure and applications
- Collaborating with global cyber security teams on strategic security projects
- Deploy and own Sentinel in the Defender portal, data connectors across Entra, Defender XDR, M365 and SaaS sources, plus the retention and tiering decisions that keep ingestion cost defensible
- Scripting and automation experience (PowerShell, Python, KQL) and familiarity with Sentinel automation/orchestration or similar tools
- Experience implementing automation using Logic Apps and Playbooks for alert enrichment and incident response
- Ability to analyze and interpret complex security data, develop actionable insights, and perform threat hunting
- Experience generating compliance and security posture reports and ensuring logging/monitoring meet regulatory requirements
- understanding of modern detection and response concepts, including alerting, analytics and basic incident response workflows
- understanding of Threat Intelligence, landscape, attacker behavior, MITRE ATT&CK and pattern recognition is a plus
- Strong analytical skills and ability to translate security requirements into technical solutions
- Strong initiative and willingness to take ownership of technical tasks and projects and grow responsibility over time
- Ability to work independently and collaboratively in cross-functional teams
- Very good written and spoken English, German is a plus
- Relevant Microsoft certifications (e.g., SC-100, SC-200, SC-300, SC-401) is a plus
Place of work:
Budapest