Azure Cloud Sentinel Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
Our client, a Fortune 500 financial technology company, is hiring an Azure Sentinel Engineer to support a federal government program. This is hands-on detection engineering in an Azure Government (GovCloud) environment - building the security monitoring capability, not triaging alerts on someone else’s.
You’ll own Microsoft Sentinel end to end: onboarding data sources, writing and tuning KQL analytics rules, building automated response playbooks, and hunting threats alongside the SOC. The program operates under FedRAMP and FISMA, so security work here is measured against real federal controls.
What You’ll Do
- Design, implement, and maintain Microsoft Sentinel SIEM/SOAR
- Onboard and manage security data sources into Azure Log Analytics - Syslog, CEF, REST APIs, threat intelligence feeds
- Write and tune KQL queries, analytics rules, alerts, and workbooks
- Build automated response playbooks with Azure Logic Apps
- Perform threat hunting, incident investigation, and response with SOC teams
- Implement Azure security controls aligned to Zero Trust
- Assess vulnerabilities, analyze attacker TTPs, and drive remediation
- Support cloud security governance, compliance, and audit activity across FedRAMP and FISMA requirements
- Provide security architecture guidance on cloud security strategy
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field
- 5+ years cybersecurity experience with substantial hands-on Microsoft Sentinel administration and engineering
- Hands-on, current experience (within the last 12 months) with: Microsoft Sentinel, Azure Log Analytics, Kusto Query Language (KQL), Azure Logic Apps, Microsoft Defender suite, Azure security and identity services
- Privileged Access Management (PAM) and Identity and Access Management concepts
- CI/CD security and application security scanning
- Configuring and securing enterprise Azure environments
- Working knowledge of Zero Trust architecture and cloud security best practices
- US Citizen or Green Card holder with 3+ years continuous US residence and work history. No offshore work within that window. Federal background check required - allow 4-8 weeks.
- Willing and able to work onsite in Marietta, GA five days per week
- Open to converting to full-time employment with the client
Preferred
- Azure Government (GovCloud) experience
- FISMA, FedRAMP, and NIST 800-53 compliance experience
- Certifications: SC-200, AZ-500, SC-100, CISSP, CCSP - current, not lapsed
- Microsoft Defender XDR: Defender for Endpoint, Office 365, Identity, Cloud Apps
- Data protection: Microsoft Purview, MIP, DLP, Key Vault
- Identity: Entra ID, PIM, Conditional Access, Azure Lighthouse
- Experience migrating an organization from Splunk, QRadar, ArcSight, or LogRhythm onto Sentinel
- Prior work with government clients, auditors, and executive stakeholders
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.experis.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Data Analyst Salary in the UK
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
Is Software Engineering Over-Saturated?
7 Cloud Computing Trends Coming in 2025 for Developers