Sr. Cybersecurity Engineer, Cloud and Incident Response
WIDENET CONSULTING, LLC
Seattle, WA, United States
15 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on widenet-consulting.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$176,800.0 - $197,600.0
Working hours
Regular working hours
Job source
Tech stack
Automation of Tests
Microsoft Azure
Software as a Service
Cloud Computing
Cloud Computing Security
Cyber Security
Data Security
Digital Forensics
Identity and Access Management
Microsoft Security Essentials
Windows PowerShell
Kusto Query Language
+11 more
Zero Trust Network Access
Microsoft SharePoint
Security Information and Event Management
Data Classification
Software Security
Mitre Att&ck
Multi-Cloud
Microsoft InTune
Tanium Platform Expertise
Palo Alto Networks
Microsoft Sentinel
Job description
Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.
This position will help strengthen the cloud security posture, mature incident response capabilities, and advance data security and zero-trust initiatives.
Responsibilities Cloud security:
- Harden Azure and multi-cloud environments against recognized benchmarks and cloud security posture findings
- Remediate Defender for Cloud findings and drive measurable secure score improvement
- Implement workload protection, configuration baselines, and infrastructure-as-code security checks
- Address cloud identity and entitlement risk, including overprivileged roles, service principals, and standing access
Incident response:
- Enhance and operationalize incident response playbooks aligned to NIST SP 800-61
- Lead and support investigations across cloud, identity, endpoint, email, and SaaS, including account compromise, data exfiltration, insider risk, and business email compromise
- Perform containment, eradication, recovery, evidence preservation, and post-incident reporting
- Coordinate with the managed detection and response provider on escalation quality, handoff, and case closure
- Design and facilitate tabletop exercises and translate findings into control improvements
SIEM optimization and detection engineering:
- Tune Microsoft Sentinel for signal quality and cost efficiency, including connector selection, ingestion tiering, and table-level retention decisions
- Author and maintain analytic rules and hunting queries in KQL
- Map detection coverage to MITRE ATT&CK and close identified gaps
- Reduce false positive volume and improve alert enrichment and automation through SOAR playbooks
Data security and DLP:
- Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps
- Implement sensitivity labels, auto-labeling, and data classification at scale
- Operate Insider Risk Management and support eDiscovery and investigative requests
- Drive DLP findings to closure through policy change, access revocation, or corrective action, not just alerting
Zero trust:
- Advance zero trust maturity across identity, device, network, application, and data pillars
- Implement and refine conditional access, privileged identity management, device compliance, and least privilege access models
- Support segmentation and egress control initiatives
Requirements
7+ years in security engineering or security operations
- Deep hands-on Microsoft security stack experience: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune
- Direct, demonstrable Microsoft Purview experience across DLP, sensitivity labels, and Insider Risk Management
- Strong KQL authoring ability, including detection development and investigative hunting
- Demonstrated incident response leadership on real incidents, not tabletop only
- Azure cloud security depth, including identity, networking, and workload protection
- PowerShell and Microsoft Graph API automation
- Clear written communication for both technical peers and executive audiences
Preferred
- Experience in a lean security team where the role spans engineering and operations
- Familiarity with Palo Alto Networks, Tanium, and CASB or SSPM platforms
- Digital forensics experience, including cloud and M365 artifact analysis
- Experience working alongside an MXDR or managed SOC provider
- Certifications: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, CISSP
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on widenet-consulting.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago