Home / Careers

Careers

We're a small team building the agentic SOC for multi-tenant Microsoft Sentinel. The work is close to real incidents, real customers and real analysts, and each person owns a large part of the product.

Work on real SOCsYour code runs against live Sentinel tenants and changes how analysts spend their day.
Small team, wide scopeNo narrow tickets. You own problems from design to production and talk directly to customers.
Remote, anywhere in the worldWork from wherever you do your best work. Our hubs are in Kathmandu and San Francisco.
Open roles

Join us

3 open positions · Apply at info@cybersentinal.tech

SOAR Engineer

EngineeringRemote, anywhere in the worldFull-time

You'll build the automation that turns an agent's decision into a safe, audited action across many customer tenants.

What you'll do

  • Build and maintain Sentinel playbooks with Logic Apps and automation rules
  • Write response actions for Defender XDR, Entra ID and Microsoft Graph, with approval gates
  • Integrate with PSA and ITSM tools such as ConnectWise, HaloPSA, Zoho and ServiceNow
  • Design approval and escalation flows in Microsoft Teams
  • Make every action least-privilege, idempotent and fully logged

What you bring

  • 3+ years in security automation or SOAR
  • Hands-on Logic Apps or Power Automate, plus Python or PowerShell
  • Solid REST API and Microsoft Graph experience
  • Working knowledge of KQL and Microsoft Sentinel
  • Nice to have: Azure Functions, Bicep or ARM, MSSP experience
Apply for this role

Fullstack Forward Deployed Engineer

EngineeringRemote, anywhere in the worldFull-time

You'll sit between our customers and our product: onboarding MSSPs and enterprise SOCs, then shipping the features they need end to end.

What you'll do

  • Onboard customer tenants through Azure Lighthouse and run pilots with their analysts
  • Tailor runbooks, autonomy levels and integrations for each customer
  • Build product features across the stack, from UI to APIs to agent tooling
  • Turn what you learn in the field into product priorities
  • Travel to customers when it helps

What you bring

  • 4+ years of full-stack engineering (TypeScript and React, plus Python or C#)
  • Experience deploying on Azure
  • Comfort working directly with technical customers
  • Experience building with LLMs and agent tooling
  • Nice to have: SOC, SIEM or MSSP background
Apply for this role

SIEM Engineer

SecurityRemote, anywhere in the worldFull-time

You'll own detection quality and data health across every Sentinel workspace we manage, so the agents always have good signal to work with.

What you'll do

  • Write and tune analytics rules and hunting queries in KQL
  • Onboard and maintain data connectors, DCRs and ASIM parsers
  • Map detection coverage to MITRE ATT&CK and close the gaps
  • Manage ingestion cost with the right log tiers across tenants
  • Build workbooks and reports for customers and our own operations

What you bring

  • 3+ years with Microsoft Sentinel or another enterprise SIEM
  • Strong KQL and an understanding of Defender XDR advanced hunting
  • Experience with AMA, DCRs and multi-workspace setups
  • Good instincts for separating signal from noise
  • Nice to have: SC-200, MSSP experience, detection-as-code
Apply for this role

How we hire

  1. Intro call30 minutes about you, the role and the team.
  2. Technical conversationA practical discussion based on real work, not puzzles.
  3. Working sessionA short paid exercise or a pairing session, your choice.
  4. Meet the teamTalk to the people you'll work with, then a decision within a week.
Don't see your role?We're always glad to hear from strong security and engineering people. Send your CV to info@cybersentinal.tech.
Send an open application