Azure Cloud Sentinel Engineer

Experis
Marietta, GA, United States
4 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Azure Cloud Computing Cloud Computing Security System Configuration Microsoft Office ArcSight SIEM Tool Zero Trust Network Access EndPointSecurity Software Security QRadar Microsoft Sentinel Splunk
+1 more
Key Vault

Job description

Our client, a Fortune 500 financial technology company, is hiring an Azure Sentinel Engineer to support a federal government program. This is hands-on detection engineering in an Azure Government (GovCloud) environment - building the security monitoring capability, not triaging alerts on someone else’s.

You’ll own Microsoft Sentinel end to end: onboarding data sources, writing and tuning KQL analytics rules, building automated response playbooks, and hunting threats alongside the SOC. The program operates under FedRAMP and FISMA, so security work here is measured against real federal controls.

What You’ll Do

  • Design, implement, and maintain Microsoft Sentinel SIEM/SOAR
  • Onboard and manage security data sources into Azure Log Analytics - Syslog, CEF, REST APIs, threat intelligence feeds
  • Write and tune KQL queries, analytics rules, alerts, and workbooks
  • Build automated response playbooks with Azure Logic Apps
  • Perform threat hunting, incident investigation, and response with SOC teams
  • Implement Azure security controls aligned to Zero Trust
  • Assess vulnerabilities, analyze attacker TTPs, and drive remediation
  • Support cloud security governance, compliance, and audit activity across FedRAMP and FISMA requirements
  • Provide security architecture guidance on cloud security strategy

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field
  • 5+ years cybersecurity experience with substantial hands-on Microsoft Sentinel administration and engineering
  • Hands-on, current experience (within the last 12 months) with: Microsoft Sentinel, Azure Log Analytics, Kusto Query Language (KQL), Azure Logic Apps, Microsoft Defender suite, Azure security and identity services
  • Privileged Access Management (PAM) and Identity and Access Management concepts
  • CI/CD security and application security scanning
  • Configuring and securing enterprise Azure environments
  • Working knowledge of Zero Trust architecture and cloud security best practices
  • US Citizen or Green Card holder with 3+ years continuous US residence and work history. No offshore work within that window. Federal background check required - allow 4-8 weeks.
  • Willing and able to work onsite in Marietta, GA five days per week
  • Open to converting to full-time employment with the client

Preferred

  • Azure Government (GovCloud) experience
  • FISMA, FedRAMP, and NIST 800-53 compliance experience
  • Certifications: SC-200, AZ-500, SC-100, CISSP, CCSP - current, not lapsed
  • Microsoft Defender XDR: Defender for Endpoint, Office 365, Identity, Cloud Apps
  • Data protection: Microsoft Purview, MIP, DLP, Key Vault
  • Identity: Entra ID, PIM, Conditional Access, Azure Lighthouse
  • Experience migrating an organization from Splunk, QRadar, ArcSight, or LogRhythm onto Sentinel
  • Prior work with government clients, auditors, and executive stakeholders

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.experis.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:18 min

Automating infrastructure mitigation via Azure Monitor integrations

Mike Mike · WWC 2025

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:55 min

Centralizing credentials management using Azure Key Vault resource integration

Marcel Lupo · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:03 min

Implementing secured configuration vaults via Azure

Markus Möller · WWC 2021

2:21 min

Structuring the backend architecture of machine learning workspaces

Jose Luis Latorre Millas · LIVE

Videos

See all

Related articles

See all