What you will do:
- Design, implement, and maintain Microsoft Sentinel SIEM/SOAR solutions.
- Ingest and manage security data sources into Azure Log Analytics (Syslog, CEF, APIs, Threat Intelligence feeds).
- Develop and tune KQL queries, analytics rules, alerts, and dashboards.
- Build automated response playbooks using Azure Logic Apps and Microsoft Copilot for Security.
- Perform threat hunting, incident investigation, and response activities with SOC teams.
- Implement and manage Azure security controls aligned with Zero Trust principles.
- Assess vulnerabilities, analyze attacker TTPs, and support remediation efforts.
- Support cloud security governance, compliance, and audit activities, including FedRAMP and FISMA requirements.
- Provide security architecture guidance and contribute to cloud security strategy initiatives.
What you need:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field.
- 5+ years of cybersecurity experience, including 5+ years of hands-on Microsoft Sentinel administration and engineering.
- Strong experience with: Microsoft Sentinel, Azure Log Analytics, Kusto Query Language (KQL), Azure Logic Apps, Microsoft Defender Suite, Azure Security and Identity Services, Privileged Access Management (PAM), CI/CD security and application security scanning, Experience configuring and securing enterprise Azure environments.
- Knowledge of Zero Trust architecture and cloud security best-practices.
Preferred Skills:
- Azure Government (GovCloud) experience.
- Experience supporting FISMA, FedRAMP, and NIST compliance frameworks.
- Relevant certifications such as: CISSP, CCSP, Microsoft Azure Security Engineer Associate, Microsoft Cybersecurity Architect Expert.
- Experience collaborating with government clients, auditors, and executive stakeholders.
- Additional Technical Expertise
- Microsoft Defender XDR: Defender for Endpoint, Office 365, Identity, and Cloud Apps; Data Protection: Microsoft Purview, MIP, DLP, Key Vault
- Identity & Access Management: Entra ID (Azure AD), PIM, Conditional Access, Azure Lighthouse, Zero Trust
- Cloud Security: Azure Security Services, M365 Security, Multi-Cloud IAM