The Texas Department of State Health Services (DSHS) is looking to solve advanced software development problems focused on designing, building, testing, and optimizing Microsoft Sentinel capabilities for DSHS projects.
Requirements
- Microsoft Sentinel architecture, SOAR, and UEBA capabilities.
- Azure cloud services, Logic Apps, Azure Functions, Event Hubs, Key Vault, and Azure AD.
- Security operations processes (triage, threat detection, incident response, threat modeling).
- MITRE ATT&CK, NIST CSF, Zero Trust Architecture concepts.
- Programming and scripting languages (Python, PowerShell, KQL, C-Sharp, JavaScript, or equivalent).
- CI/CD pipelines, DevOps practices, and Git-based version control.
- API integrations and JSON/YAML structures.
Responsibilities
- Designs, develops, tests, and deploys Sentinel SOAR automation playbooks using Azure Logic Apps, Azure Functions, ARM templates, and REST APIs.
- Creates automated workflows for alert enrichment, triage, response actions, notification processes, and case management.
- Integrates Sentinel with third-party systems (EDR, IAM, ticketing systems, email gateways, firewalls, etc.) to automate security operations.
- Develops custom UEBA detection rules, anomaly models, ML-based behavior patterns, and advanced hunting queries (KQL).
- Builds and maintains analytics content, data parsers, normalization rules, and entity behavior profiles.
- Designs and implements custom data connectors, ingestion pipelines, and data transformation logic.
- Develops supporting code modules, scripts, microservices, and helper APIs using Python, PowerShell, .NET, or similar languages.
Other
- Graduation from an accredited four-year college or university with major coursework in computer science, computer information systems, software engineering, cybersecurity, or a related field.
- Four (4) years of experience in software development, cloud engineering, SIEM engineering, or cybersecurity engineering.
- Ability to work independently and take ownership of complex development tasks.
- Ability to translate security requirements into scalable technical solutions.
- Ability to manage multiple work assignments and meet deadlines.
- Experience working in a government, healthcare, or regulatory environment.