> Markdown version of [/jobs/ext/2709039-microsoft-security-automation-incident-response-engineer](https://www.wearedevelopers.com/jobs/ext/2709039-microsoft-security-automation-incident-response-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Microsoft Security Automation & Incident Response Engineer - **Company:** Magnet Forensics - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Cloud Computing, Cyber Security, Intrusion Detection and Prevention, Microsoft Security Essentials, Kusto Query Language, Security Information and Event Management, Systems Integration, Microsoft Power Automate, Azure Security Center, Cybercrime, Microsoft Sentinel, Security Orchestration, Automation & Response - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/microsoft-security-automation-incident-response-engineer-contract-position-magnet-forensics-8742847 ## About the Role * 5+ years in Security Operations, Detection Engineering, or Incident Response * Strong Microsoft Sentinel experience * Strong Microsoft Defender suite experience * Advanced KQL skills * Logic Apps experience * SOAR automation experience * SIEM engineering experience * Security operations workflow optimization experience Preferred Qualifications * Microsoft Security certifications * Threat hunting experience * Detection engineering background * Experience integrating third-party security telemetry * Exposure to Purview and DLP technologies ## Description Magnet Forensics is seeking a highly skilled Microsoft Security Automation & Incident Response Engineer to accelerate the maturity and efficiency of our security operations program. This resource will be responsible for optimizing and integrating Microsoft's security platform, reducing manual analyst workload, automating repetitive tasks, improving detection coverage, and enhancing incident response capabilities. The ideal candidate is a hands-on engineer with deep experience in Microsoft Sentinel, Defender XDR, automation, and modern security operations. This is a 3-4 month contract role What You'll Do Security Operations Optimization * Analyze existing alert triage and incident response processes * Identify operational bottlenecks and manual activities * Implement improvements that reduce analyst effort and response times * Improve overall SOC efficiency and effectiveness Detection Engineering * Tune Microsoft Sentinel analytics rules * Reduce false positives and alert fatigue * Create advanced correlation rules and hunting content * Improve quality and fidelity of security detections Security Automation Design and implement automation for: * Alert enrichment * Incident routing * Ticket creation * Escalation workflows * Investigation support * Standard response actions Platform Integration Optimize and integrate: * Microsoft Sentinel * Microsoft Defender XDR * Microsoft Defender for Endpoint * Microsoft Defender for Identity * Microsoft Defender for Cloud Apps * Entra ID * Zscaler telemetry * Existing ITSM and ticketing platforms Incident Response Support * Improve incident response processes * Enhance investigation playbooks * Develop response automation * Create operational runbooks and documentation ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)