Microsoft Security Automation & Incident Response Engineer

Magnet Forensics
United States
7 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Cyber Security Intrusion Detection and Prevention Microsoft Security Essentials Kusto Query Language Security Information and Event Management Systems Integration Microsoft Power Automate Azure Security Center Cybercrime Microsoft Sentinel Security Orchestration, Automation & Response

Job description

Magnet Forensics is seeking a highly skilled Microsoft Security Automation & Incident Response Engineer to accelerate the maturity and efficiency of our security operations program.

This resource will be responsible for optimizing and integrating Microsoft’s security platform, reducing manual analyst workload, automating repetitive tasks, improving detection coverage, and enhancing incident response capabilities.

The ideal candidate is a hands-on engineer with deep experience in Microsoft Sentinel, Defender XDR, automation, and modern security operations.

This is a 3-4 month contract role

What You’ll Do

Security Operations Optimization

  • Analyze existing alert triage and incident response processes
  • Identify operational bottlenecks and manual activities
  • Implement improvements that reduce analyst effort and response times
  • Improve overall SOC efficiency and effectiveness Detection Engineering

  • Tune Microsoft Sentinel analytics rules
  • Reduce false positives and alert fatigue
  • Create advanced correlation rules and hunting content
  • Improve quality and fidelity of security detections Security Automation Design and implement automation for:

  • Alert enrichment
  • Incident routing
  • Ticket creation
  • Escalation workflows
  • Investigation support
  • Standard response actions Platform Integration Optimize and integrate:

  • Microsoft Sentinel
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps
  • Entra ID
  • Zscaler telemetry
  • Existing ITSM and ticketing platforms Incident Response Support

  • Improve incident response processes
  • Enhance investigation playbooks
  • Develop response automation
  • Create operational runbooks and documentation

Requirements

  • 5+ years in Security Operations, Detection Engineering, or Incident Response
  • Strong Microsoft Sentinel experience
  • Strong Microsoft Defender suite experience
  • Advanced KQL skills
  • Logic Apps experience
  • SOAR automation experience
  • SIEM engineering experience
  • Security operations workflow optimization experience Preferred Qualifications

  • Microsoft Security certifications
  • Threat hunting experience
  • Detection engineering background
  • Experience integrating third-party security telemetry
  • Exposure to Purview and DLP technologies

About the company

Magnet Forensics is a global leader in the development of digital investigative software that acquires, analyzes, and shares evidence from computers, smartphones, tablets, and IoT-related devices. We are continually innovating so our customers can deploy advanced and effective tools to protect their companies, communities, and countries. Serving thousands of customers globally, our solutions are playing a crucial role in modernizing digital investigations, helping investigators fight crime, protect assets, and guard national security. With employees based around the world, Magnet Forensics has been expanding our global presence. As a part of Magnet Forensics, you can expect to make a difference in the world, no matter what role you play. You’ll be supported through learning and development, not to mention an incredible team with unbelievable talent and integrity., At Magnet Forensics, we take a hybrid-flexible approach to support your productivity and work-life balance. If you’re within a comfortable travel distance to one of our offices, you’ll occasionally join us in person. How often you’ll come in depends on your department and team needs, typically ranging from weekly to monthly. These in-person moments help us build stronger connections, spark new ideas, and celebrate our successes together. Most days, you can choose what works best for you, while staying in tune with your team’s goals.

We’re excited to welcome you to our team and look forward to achieving great things together - both in the office and wherever you work best!

The Most Important Thing

We’re looking for candidates that can provide examples of how they have demonstrated Magnet CODE in their previous experiences:

CARE - We care about each other and our mission to make a difference in the world.

OWN - We are accountable for our results - while never forgetting to act with integrity, empathy, and respect.

DEDICATE - We put our heart and soul into meeting the needs of our customers and helping them serve the people they protect.

EVOLVE - We are constantly innovating and exploring new ways to work together to make an impact with our work.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo ¡ World Congress 2024

1:18 min

Automating infrastructure mitigation via Azure Monitor integrations

Mike Mike ¡ World Congress 2025

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 ¡ World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

Videos

See all

Related articles

See all