Microsoft Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions., * Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR
- Engineering and optimisation of SIEM capabilities across enterprise environments
- Developing and tuning KQL queries, analytics and detection rules
- Designing and implementing SOC automation, playbooks and scripting
- Improving security event detection and response capabilities
- Conducting Microsoft tenant health checks, security audits and architecture reviews
- Analysing cloud security risks and recommending appropriate security controls
- Supporting complex incident triage and resolution
- Designing and documenting security engineering standards and processes
- Researching and implementing new Microsoft security capabilities
- Producing high-quality technical and customer-facing documentation
- Working directly with customers and technical stakeholders
- Supporting and mentoring more junior members of the engineering team
Requirements
We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments., To be considered, you should have strong commercial experience across the following:
- Microsoft Sentinel / Azure Sentinel
- Microsoft Defender / Defender XDR
- Strong KQL / Kusto Query Language capability
- Security Engineering, SOC Engineering or Microsoft Security Consulting
- SIEM engineering rather than solely alert monitoring or incident triage
- Detection engineering and security monitoring optimisation
- Automation, scripting, SOAR or Sentinel playbooks
- Cloud security assessments, controls and risk analysis
- Designing and documenting security processes
- Customer-facing technical delivery
Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position.
Highly Desirable
Experience across any of the following would be particularly valuable:
- Microsoft Purview
- Microsoft Defender for Endpoint
- Defender for Cloud
- Defender for Identity
- Defender for Office 365
- Microsoft Entra ID
- Intune
- Azure security architecture
- Logic Apps / Sentinel playbooks
- PowerShell or Python
- MITRE ATT&CK
- Microsoft Security architecture and tenant assessments
Previous experience working directly for Microsoft, or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Is Software Engineering Over-Saturated?
Where To Find Software Engineering Jobs
Why Upskilling And Reskilling is Important For Developers