> Markdown version of [/jobs/ext/2826249-content-engineer](https://www.wearedevelopers.com/jobs/ext/2826249-content-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Content Engineer - **Company:** PRIVATE INNOVATION LLC - **Location:** Milpitas, CA, United States - **Contract:** Permanent contract - **Skills:** Microsoft Windows, JIRA, Cyber Security, System Configuration, Logic Synthesis of Circuits, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Domain Name System Security Extensions, Domain Name System (DNS), Intrusion Detection and Prevention, Python (Programming Language), Microsoft Office, Parsing, Windows PowerShell, Kusto Query Language, Security Information and Event Management, Microsoft Power Automate, Mitre Att&ck, Cyber Threat Analysis, Cloudflare, Microsoft Sentinel, Api Management, Servicenow - **Published:** September 10, 2026 - **Apply:** https://www.dice.com/job-detail/ff2229fd-c01d-4301-a1a7-ee324cdc9f8b ## About the Role * EDR Policy & Configuration * Microsoft Defender XDR * CrowdStrike Falcon * SOAR & Automation ## Description We are seeking a Content Engineer to support the security operations function with a strong focus on hands-on configuration and tuning of security platforms. The role will work across Microsoft Defender, Microsoft 365 security configurations, CrowdStrike, and Sublime Security to align security controls with corporate policies and reduce organizational risk. The ideal candidate will have strong automation skills to streamline content deployment, reduce manual effort, and maintain consistency across security platforms. The role will also involve reviewing control coverage, identifying gaps, and implementing remediation to strengthen the overall security posture. Key Responsibilities / Skills * SIEM / Detection Engineering * KQL, SPL, YARA-L, Sigma * Detection logic design, false-positive tuning, detection-as-code * MITRE ATT&CK mapping and coverage gap analysis * Log source onboarding, parsing, normalization, and field mapping * Alert triage pipeline design, enrichment, severity, and suppression EDR Policy & Configuration * Microsoft Defender XDR, ASR rules, tamper protection, exclusions, custom detections * CrowdStrike Falcon, prevention policies, sensor grouping, IOA rules, Fusion SOAR, RTR * EDR exclusion governance and endpoint telemetry tuning DNS Security * Infoblox BloxOne * Cloudflare Gateway * DNS threat analysis including DGA, DNS tunneling, and beaconing Email Security * Sublime Security * Microsoft Defender for Office 365 * Proofpoint / Mimecast * SPF/DKIM/DMARC and email header analysis SOAR & Automation * Microsoft Sentinel Playbooks / Logic Apps * VirusTotal, Shodan, WHOIS, and threat-intelligence API integrations * ServiceNow / Jira workflow automation * Python / PowerShell scripting