Zero Trust Security Engineer - Senior
Role details
Job location
Tech stack
Job description
DecisionPoint Corporation is seeking a Zero Trust Security Engineer - Senior to help lead the implementation and operational integration of Zero Trust Architecture (ZTA) across GPO enterprise systems. This role is responsible for managing Microsoft Sentinel integration, optimizing SIEM log ingestion workflows, and administering advanced detection and response capabilities. Reporting to the ZTA SME, this role ensures timely implementation of Sentinel rule sets, threat intelligence sharing, and continuous feedback loops to maintain a proactive and adaptive cybersecurity defense aligned with Zero Trust principles., Zero Trust Security Engineer - Senior will:
- Configure and maintain Microsoft Sentinel environments across GPO systems.
- Implement and continuously improve correlation rules, analytic rules, and hunting queries.
- Support continuous deployment pipelines for updated detection logic and baselines.
- Oversee ingestion, normalization, and parsing of security log data from diverse data sources.
- Ensure compatibility with CEF, Syslog, and other common log formats.
- Monitor and troubleshoot ingestion performance and scalability issues across on-premise and cloud systems.
- Distribute actionable threat intelligence to security teams and mission stakeholders.
- Integrate threat intel feeds into Sentinel and support adaptive tuning of detection content based on real-time insights.
- Recommend hardening strategies and lessons-learned improvements across the enterprise.
Requirements
Location: Remote - candidates located in the Washington, DC metropolitan area (DMV) are highly preferred. Clearance Requirement: Must be able to obtain and maintain a Public Trust clearance., + Minimum Experience: 8 years of experience in cybersecurity operations, SIEM engineering, or log management.
- Minimum Education: Bachelor's degree in Computer Science, Information Systems, other related disciplines (or equivalent experience)
- Technical Knowledge: Hands-on expertise with Microsoft Sentinel, KQL, Azure Log Analytics, and data connectors. Strong understanding of threat intelligence frameworks and cyber kill chains.
- Federal experience (preferred)
- Certifications: Microsoft Certified: Security Operations Analyst Associate (SC-200), GIAC Security Operations Certified (GSOC), CompTIA CySA+, or CISSP (Certified Information Systems Security Professional).