> Markdown version of [/jobs/ext/2172163-sr-cybersecurity-engineer-cloud-and-incident-response](https://www.wearedevelopers.com/jobs/ext/2172163-sr-cybersecurity-engineer-cloud-and-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Cybersecurity Engineer, Cloud and Incident Response - **Company:** WIDENET CONSULTING, LLC - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $176,800.0 - $197,600.0 - **Contract:** Permanent contract - **Skills:** Automation of Tests, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Data Security, Digital Forensics, Identity and Access Management, Microsoft Security Essentials, Windows PowerShell, Kusto Query Language, Zero Trust Network Access, Microsoft SharePoint, Security Information and Event Management, Data Classification, Software Security, Mitre Att&ck, Multi-Cloud, Microsoft InTune, Tanium Platform Expertise, Palo Alto Networks, Microsoft Sentinel - **Published:** August 21, 2026 - **Apply:** https://widenet-consulting.com/openings/7018/#apply-now ## About the Role 7+ years in security engineering or security operations - Deep hands-on Microsoft security stack experience: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune - Direct, demonstrable Microsoft Purview experience across DLP, sensitivity labels, and Insider Risk Management - Strong KQL authoring ability, including detection development and investigative hunting - Demonstrated incident response leadership on real incidents, not tabletop only - Azure cloud security depth, including identity, networking, and workload protection - PowerShell and Microsoft Graph API automation - Clear written communication for both technical peers and executive audiences Preferred - Experience in a lean security team where the role spans engineering and operations - Familiarity with Palo Alto Networks, Tanium, and CASB or SSPM platforms - Digital forensics experience, including cloud and M365 artifact analysis - Experience working alongside an MXDR or managed SOC provider - Certifications: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, CISSP ## Description Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST. This position will help strengthen the cloud security posture, mature incident response capabilities, and advance data security and zero-trust initiatives. Responsibilities Cloud security: - Harden Azure and multi-cloud environments against recognized benchmarks and cloud security posture findings - Remediate Defender for Cloud findings and drive measurable secure score improvement - Implement workload protection, configuration baselines, and infrastructure-as-code security checks - Address cloud identity and entitlement risk, including overprivileged roles, service principals, and standing access Incident response: - Enhance and operationalize incident response playbooks aligned to NIST SP 800-61 - Lead and support investigations across cloud, identity, endpoint, email, and SaaS, including account compromise, data exfiltration, insider risk, and business email compromise - Perform containment, eradication, recovery, evidence preservation, and post-incident reporting - Coordinate with the managed detection and response provider on escalation quality, handoff, and case closure - Design and facilitate tabletop exercises and translate findings into control improvements SIEM optimization and detection engineering: - Tune Microsoft Sentinel for signal quality and cost efficiency, including connector selection, ingestion tiering, and table-level retention decisions - Author and maintain analytic rules and hunting queries in KQL - Map detection coverage to MITRE ATT&CK and close identified gaps - Reduce false positive volume and improve alert enrichment and automation through SOAR playbooks Data security and DLP: - Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps - Implement sensitivity labels, auto-labeling, and data classification at scale - Operate Insider Risk Management and support eDiscovery and investigative requests - Drive DLP findings to closure through policy change, access revocation, or corrective action, not just alerting Zero trust: - Advance zero trust maturity across identity, device, network, application, and data pillars - Implement and refine conditional access, privileged identity management, device compliance, and least privilege access models - Support segmentation and egress control initiatives ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)