Lead Consultant - Service Management(Sentinel)
AstraZeneca · India - Chennai
AstraZeneca · India - Chennai
Job Title: Lead Consultant - Service Management(Sentinel) GCL: E Introduction to role: Are you ready to take end-to-end ownership of enterprise security solutions and turn telemetry into decisive protection outcomesThis role leads the platforms that keep our science moving safely and quickly. It ensures data and insights flow reliably across a global, hybrid environment. This allows teams to focus on delivering life-changing medicine. s. Based in Chennai and working across regions, you will lead technical services for Microsoft Sentinel and Cribl. You will build how telemetry is routed, normalized, and used for investigation and response. If you thrive on solving complex, cross-platform challenges and influencing strategic direction through hands-on excellence, this is your stage to make measurable impact. Accountabilities: Technical Service Leadership: Own service performance, resilience, and stability for security tooling across regions, driving consistent delivery according to organizational standards and frameworks. Platform Administration and Ownership: Configure, operate, and continually improve core security platforms to meet SLAs, ensure supportability, and scale with demand. Telemetry Pipeline Leadership with Cribl: Engineer and coordinate routing, decoding, modification, augmentation, and tuning to deliver efficient, governed, cost-effective data pipelines to downstream systems. SIEM Administration and Operations involving Microsoft Sentinel: Manage connectors, onboarding, normalization, KQL issue solving and optimization, enabling data analysis, reporting interfaces, automation, retention, RBAC, and platform health. Enterprise Standards and Process Build: Define and refine service models, tooling criteria, and operational procedures that raise maturity and enable predictable delivery. Security Tooling Integrations: Build and sustain integrations across SIEM, endpoint, identity, cloud, network, storage, and ITSM to ensure interoperability, data quality, and conscientious support models. Monitoring, Detection, and Analytics Enablement: Enable and tune analytics rules, alerts, dashboards, and operational use cases to improve platform efficiency and response precision. Protection Tooling Enablement: Integrate and optimize endpoint and protection technologies, ensuring resilient telemetry flow and policy supportability; familiarity with Microsoft's endpoint protection solution is advantageous. Service Management and Operational Excellence: Lead incident, problem, change, release, and service reviews; promote ongoing improvement and operational rigor. Governance, Risk, and Compliance: Align services to policies, standards, audits, and regulatory expectations; assess risks and close control gaps proactively. Continuous Improvement and Transformation: Find opportunities, implement innovations, and land change with training and adoption plans that lift capability and performance. Project and Initiative Delivery: Lead complex onboarding, integrations, migrations, upgrades, and modernization initiatives to agreed quality, security, and timeline targets. Collaborator Engagement and Strategic Influence: Communicate performance and risk to technical and senior collaborators; build priorities and investment for enterprise outcomes. Technical Oversight and Supplier Management: Guide internal teams and external partners to deliver quality, supportability, and measurable improvements. External Partnerships and Innovation: Leverage vendor and industry relationships to introduce practices and solutions that advance the tooling estate. Specialist Expertise and Mentoring: Act as the go-to problem solver; set standards, share knowledge, and mentor engineers and analysts. AI-Enabled Security: Apply and evaluate AI and ML for automation, anomaly detection, enrichment, investigation support, workflow optimization, and content tuning with appropriate governance. Essential Skills/Experience: • Typically 7+ years of experience in cyber security technologies and processes, with substantial hands-on experience in engineering security tools, platform administration, and day-to-day system maintenance within large enterprise environments. • Strong cyber security background with practical experience operating and supporting enterprise platforms used for monitoring, telemetry management, investigation, detection, response, and protection. • Strong hands-on expertise with Cribl, including telemetry routing, stream or pipeline management, parsing, transformation, enrichment, filtering, masking, resolving challenges, performance tuning, and operational administration in enterprise environments. • Strong hands-on experience working on Microsoft Sentinel, including administration of data connectors, telemetry onboarding, SIEM configuration, KQL-based query and resolving issues, analytics enablement, dashboards or workbooks, automation support, retention settings, access controls, and operational support of a cloud-native SIEM platform. • Good experience with platform configuration, upgrades, resolving issues, telemetry onboarding, connector or agent management, service reliability, and operational optimization at scale. • Experience working across multiple security technologies, ideally covering combinations of SIEM, telemetry pipelines, endpoint security, cloud security, identity tooling, and network security. • Demonstrated expertise in developing, implementing, and optimizing cyber security strategies, frameworks, standards, and operating models within the security tooling domain. • Substantial experience with security risk identification and assessment across enterprise technologies, with good understanding of telemetry analysis, operational issue inve