Senior Cybersecurity Engineer

TELEION, LLC
Seattle, WA, United States
5 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$155,000.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Microsoft Azure Cloud Computing Cyber Security Data Security Digital Forensics Intrusion Detection and Prevention Microsoft Security Essentials Performance Tuning Windows PowerShell Kusto Query Language Zero Trust Network Access
+6 more
Microsoft SharePoint Mitre Att&ck Multi-Cloud Microsoft InTune Microsoft Sentinel Security Orchestration, Automation & Response

Job description

Teleion is seeking a Senior Cybersecurity Engineer to strengthen cloud security posture, mature incident response capabilities, and advance data security and zero trust for our enterprise clients. This is a hands-on, client-facing contract role spanning detection engineering, real incident ownership, Microsoft Purview and DLP, and Azure cloud hardening - all within the Microsoft security ecosystem. The ideal candidate brings deep, production-configured expertise across the full Microsoft security stack and has led real incidents from containment through post-incident reporting., * Configure, tune, and operate the full Microsoft security stack in production client environments: Microsoft Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.

  • Lead incident response for real security events - account compromise, data exfiltration, insider risk, BEC - through the full lifecycle: containment, eradication, recovery, evidence preservation, and post-incident reporting.
  • Coordinate with MXDR or managed SOC providers on escalation quality, handoff, and case closure standards.
  • Author and maintain KQL analytic rules and hunting queries in Microsoft Sentinel, map detections to MITRE ATT&CK, close coverage gaps, and tune for signal quality and ingestion cost.
  • Develop SOAR playbooks to reduce false positive volume and automate analyst workflows.
  • Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps - driving findings to closure, not just alerting.
  • Implement and maintain sensitivity labels, auto-labeling at scale, Insider Risk Management, and eDiscovery support.
  • Harden Azure and multi-cloud environments against benchmarks: remediate Defender for Cloud findings, drive secure score improvement, and address cloud identity and entitlement risk.
  • Advance zero trust maturity across identity, device, network, application, and data pillars using Conditional Access, PIM, device compliance, and least-privilege access patterns.
  • Build PowerShell and Microsoft Graph API automations to scale security operations, reporting, and remediation.
  • Design and run tabletop exercises to test and mature the client’s incident response capability.

Requirements

  • 7 or more years of security engineering or security operations experience in enterprise environments.
  • Deep, production-configured hands-on experience across the full Microsoft security stack: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
  • Demonstrated leadership of real security incidents - not tabletop only - through the full lifecycle including containment, eradication, recovery, and post-incident reporting.
  • Strong KQL proficiency: authoring analytic rules, developing hunting queries, tuning for cost and signal quality, and mapping to MITRE ATT&CK.
  • Direct, demonstrable Microsoft Purview experience: DLP policy design and tuning, sensitivity labels, Insider Risk Management, and eDiscovery.
  • Experience hardening Azure environments: remediating Defender for Cloud findings, driving secure score improvement, and addressing cloud identity and entitlement risk.
  • Experience implementing zero trust controls across multiple pillars using Conditional Access, PIM, and privileged access management.
  • Proficiency in PowerShell and Microsoft Graph API for security automation.
  • Experience coordinating with MXDR or managed SOC providers on escalation and case quality.
  • Certifications preferred: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, or CISSP. Digital forensics experience in cloud and M365 environments is a plus.

About the company

Come join one of Pacific Northwest’s Best Places to work! Our culture at Teleion embodies the spirit of a startup with a sense of ownership and an employee-led business model. Employees can grow their career and have fun while doing it!, Teleion offers full benefits, PTO, holiday, 401(k). See how other employees have reviewed us on Glassdoor. We are excited to announce we have made in on Seattle Business Magazines “Washingtons Best Place to Work” for the 6th year in a row. (https://seattlebusinessmag.com/100-best-companies-work/100-best-companies-work-midsize)

Teleion is minority owned and an Equal Opportunity Employer - We welcome all races, sexual orientations, gender identities, veterans, religions and disabilities.

Salary range: $155,000 - $200,000 - Based on experience

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

1:22 min

Overcoming developer challenges in multi-cloud environments

Sandeep Pal Sandeep Pal · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all