AstraZeneca

Lead Consultant - Service Management(Sentinel)

AstraZeneca  •  Chennai, IN (Hybrid)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Job Title: Lead Consultant - Service Management(Sentinel)

GCL: E

Introduction to role:

Are you ready to take end-to-end ownership of enterprise security solutions and turn telemetry into decisive protection outcomesThis role leads the platforms that keep our science moving safely and quickly. It ensures data and insights flow reliably across a global, hybrid environment. This allows teams to focus on delivering life-changing medicine. s.

Based in Chennai and working across regions, you will lead technical services for Microsoft Sentinel and Cribl. You will build how telemetry is routed, normalized, and used for investigation and response. If you thrive on solving complex, cross-platform challenges and influencing strategic direction through hands-on excellence, this is your stage to make measurable impact.

Accountabilities:

Technical Service Leadership: Own service performance, resilience, and stability for security tooling across regions, driving consistent delivery according to organizational standards and frameworks.

Platform Administration and Ownership: Configure, operate, and continually improve core security platforms to meet SLAs, ensure supportability, and scale with demand.

Telemetry Pipeline Leadership with Cribl: Engineer and coordinate routing, decoding, modification, augmentation, and tuning to deliver efficient, governed, cost-effective data pipelines to downstream systems.

SIEM Administration and Operations involving Microsoft Sentinel: Manage connectors, onboarding, normalization, KQL issue solving and optimization, enabling data analysis, reporting interfaces, automation, retention, RBAC, and platform health.

Enterprise Standards and Process Build: Define and refine service models, tooling criteria, and operational procedures that raise maturity and enable predictable delivery.

Security Tooling Integrations: Build and sustain integrations across SIEM, endpoint, identity, cloud, network, storage, and ITSM to ensure interoperability, data quality, and conscientious support models.

Monitoring, Detection, and Analytics Enablement: Enable and tune analytics rules, alerts, dashboards, and operational use cases to improve platform efficiency and response precision.

Protection Tooling Enablement: Integrate and optimize endpoint and protection technologies, ensuring resilient telemetry flow and policy supportability; familiarity with Microsoft's endpoint protection solution is advantageous.

Service Management and Operational Excellence: Lead incident, problem, change, release, and service reviews; promote ongoing improvement and operational rigor.

Governance, Risk, and Compliance: Align services to policies, standards, audits, and regulatory expectations; assess risks and close control gaps proactively.

Continuous Improvement and Transformation: Find opportunities, implement innovations, and land change with training and adoption plans that lift capability and performance.

Project and Initiative Delivery: Lead complex onboarding, integrations, migrations, upgrades, and modernization initiatives to agreed quality, security, and timeline targets.

Collaborator Engagement and Strategic Influence: Communicate performance and risk to technical and senior collaborators; build priorities and investment for enterprise outcomes.

Technical Oversight and Supplier Management: Guide internal teams and external partners to deliver quality, supportability, and measurable improvements.

External Partnerships and Innovation: Leverage vendor and industry relationships to introduce practices and solutions that advance the tooling estate.

Specialist Expertise and Mentoring: Act as the go-to problem solver; set standards, share knowledge, and mentor engineers and analysts.

AI-Enabled Security: Apply and evaluate AI and ML for automation, anomaly detection, enrichment, investigation support, workflow optimization, and content tuning with appropriate governance.

Essential Skills/Experience:

  • Typically 7+ years of experience in cyber security technologies and processes, with substantial hands-on experience in engineering security tools, platform administration, and day-to-day system maintenance within large enterprise environments.

  • Strong cyber security background with practical experience operating and supporting enterprise platforms used for monitoring, telemetry management, investigation, detection, response, and protection.

  • Strong hands-on expertise with Cribl, including telemetry routing, stream or pipeline management, parsing, transformation, enrichment, filtering, masking, resolving challenges, performance tuning, and operational administration in enterprise environments.

  • Strong hands-on experience working on Microsoft Sentinel, including administration of data connectors, telemetry onboarding, SIEM configuration, KQL-based query and resolving issues, analytics enablement, dashboards or workbooks, automation support, retention settings, access controls, and operational support of a cloud-native SIEM platform.

  • Good experience with platform configuration, upgrades, resolving issues, telemetry onboarding, connector or agent management, service reliability, and operational optimization at scale.

  • Experience working across multiple security technologies, ideally covering combinations of SIEM, telemetry pipelines, endpoint security, cloud security, identity tooling, and network security.

  • Demonstrated expertise in developing, implementing, and optimizing cyber security strategies, frameworks, standards, and operating models within the security tooling domain.

  • Substantial experience with security risk identification and assessment across enterprise technologies, with good understanding of telemetry analysis, operational issue investigation, threat actors, attack vectors, and support for detection and response activities across tooling platforms.

  • Background in regulated and compliance-aware environments, including application of governance controls, policies, standards, procedures, audit requirements, and security data handling expectations.

  • Substantial experience collaborating with business partners and managing relationships and communications with third-party suppliers, vendors, and service partners across complex, global, and matrixed environments.

  • Good communication, collaborator engagement, prioritization, and influencing skills, with the ability to lead through change and adapt to evolving hybrid, cloud-native, and vendor-based security ecosystems.

  • Recognized internally, or able to operate, as an expert within the specialist area of security tooling and in demand as a problem solver for key technical challenges.

  • An AI-first approach, including comfort with applying, evaluating, or supporting AI and machine learning concepts in security tooling use cases.

  • Experience using scripting and automation technologies such as PowerShell, Python, or similar to improve operational efficiency, scalability, service quality, and platform supportability.

  • Bachelor’s degree or equivalent experience in information security, computer science, engineering, or a related field.

Desirable Skills/Experience:

  • Experience with Microsoft Defender for Endpoint, particularly integrated with Microsoft Sentinel, endpoint telemetry pipelines, or broader security operations workflows.

  • Experience with the wider Microsoft security ecosystem across identity, endpoint, cloud, and telemetry services.

  • Experience supporting SIEM migration, telemetry pipeline modernization, or large-scale security tooling transformation initiatives.

  • Knowledge of frameworks such as NIST CSF, ISO 27001, CIS Controls, and regulated environments such as SOX or GxP.

  • Relevant security or platform certifications aligned to Cribl, Microsoft Sentinel, cloud security, or the broader tooling domain.

  • Experience working in large, supervised, global organizations and collaborating across multicultural and geographically dispersed teams.

Why AstraZeneca:

Join a technology-forward organization where ambitious science meets data-driven engineering to unlock faster, safer delivery of medicines to patients. You will work across unexpected teams in the same room fueling ambitious thinking, from cyber engineers to scientists and product leaders, all invested in scaling secure, modern platforms. We back ambition with real investment, value patience alongside intensity, and create space to experiment through hackathons and hands-on learning. Your leadership in telemetry, SIEM, and automation will directly protect critical research, streamline global operations, and advance our transformation into a digital, data-led enterprise.

Call to Action:

Be responsible for the platforms dedicated to safeguarding breakthrough science at global scale—apply today to turn enterprise telemetry into patient impact!

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Date Posted

20-Jul-2026

Closing Date

24-Jul-2026

AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.

AstraZeneca

About AstraZeneca

We're transforming the future of healthcare by unlocking the power of what science can do for people, society and the planet. For more information, visit www.astrazeneca.com.

Community Guidelines: bit.ly/2MgAcio

Industry
Chemicals & Materials
Company Size
10,000+ employees
Headquarters
Cambridge, GB
Year Founded
Unknown
Social Media