Microsoft Security Engineer

King & Spalding LLP.
Atlanta, GA, United States
20 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Microsoft Antivirus Authentication Protocols Microsoft Azure Microsoft Online Services Software as a Service Cloud Computing Cloud Computing Security Cyber Security Information Systems System Configuration
+37 more
Information Leak Prevention Data Security Domain Name System (DNS) Identity and Access Management Issue Tracking Systems Intrusion Detection and Prevention Log Analysis Microsoft Security Essentials Microsoft Office Microsoft Software Networking Basics Performance Tuning Windows PowerShell Role-Based Access Control Azure Active Directory Cloud Services Anti-Phishing Kusto Query Language Runbook Security Information and Event Management Software Vulnerability Management Data Logging Scripting Google Cloud Microsoft Power Automate Facebook Flow Mitre Att&ck Multi-Cloud Malware Cyber Threat Analysis Microsoft InTune Azure Security Center Microsoft Fabric Information Technology Cybercrime Microsoft Sentinel CIS Benchmarks

Job description

The Microsoft Security Engineer is responsible for designing, implementing, configuring, and maintaining enterprise security capabilities across the Microsoft security ecosystem. This role supports identity protection, endpoint security, cloud security, email security, data protection, threat detection, and security operations by using Microsoft technologies such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, and related Microsoft 365 security services., * Administer, configure, and optimize Microsoft security platforms, including Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and related security services.

  • Design and implement security policies, standards, controls, and configurations that reduce risk and improve the organization’s overall security posture.
  • Manage identity and access security controls, including creating conditional access policies.
  • Support endpoint, email, identity, cloud application, and data protection security operations through effective security policies.
  • Develop and maintain detection logic, alert rules, automation, playbooks, dashboards, and operational procedures within Microsoft Sentinel and Microsoft Defender.
  • Partner with threat response, detection engineering, infrastructure, endpoint, messaging, and compliance teams to improve prevention, detection, response, and recovery capabilities.
  • Perform security health checks, configuration reviews, control validation, and hardening activities across Microsoft 365, Azure, endpoint, identity, email, and SaaS environments.
  • Support investigations associated with phishing, malware, account compromise, suspicious authentication, data exposure, endpoint threats, and cloud-based threats.
  • Analyze logs, alerts, telemetry, indicators of compromise, and threat intelligence to identify suspicious behavior and partner with detection engineering teams create proactive alerts.
  • Stay current on Microsoft security capabilities, emerging cyber threats, industry best practices, and regulatory or compliance requirements affecting enterprise security operations.
  • Participate in change management, security projects, audit support, vulnerability remediation, and after-hours incident response or on-call coverage as required.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent professional experience may be considered in lieu of a degree.
  • Minimum of 3-5 years of experience in information security, security engineering, security operations, cloud security, identity security, endpoint security, or a related IT security role.
  • Hands-on experience administering or supporting Microsoft security technologies, such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, Microsoft 365 security, or Azure security services.
  • Strong understanding of cybersecurity principles, including defense-in-depth, least privilege, identity and access management, endpoint protection, email security, cloud security, vulnerability management, logging, monitoring, and incident response.
  • Experience configuring and maintaining security policies, conditional access rules, authentication controls, endpoint security baselines, data protection policies, and alerting rules.
  • Ability to investigate security alerts, analyze logs and telemetry, identify root cause, document findings, and recommend remediation actions.
  • Working knowledge of enterprise infrastructure, including Windows, Active Directory, Azure, Microsoft 365, networking fundamentals, DNS, email flow, authentication protocols, and cloud services.
  • Experience using scripting, query, or automation tools such as PowerShell, Kusto Query Language (KQL), Microsoft Graph, Logic Apps, or similar technologies.
  • Ability to communicate technical concepts clearly to security teams, IT stakeholders, business partners, leadership, and non-technical audiences.
  • Strong analytical, troubleshooting, documentation, collaboration, and time-management skills.
  • Ability to work independently and as part of a cross-functional team in a fast-paced enterprise environment.
  • Willingness to participate in incident response, maintenance windows, and on-call rotations when required., * Microsoft security certifications such as SC-200, SC-300, SC-400, AZ-500, MS-102, or equivalent cloud/security certifications.
  • Experience with Microsoft Defender XDR incident queues, Advanced Hunting, secure score improvement, attack simulation, endpoint detection and response, email protection, identity protection, or cloud app security.
  • Experience building, tuning, or maintaining SIEM use cases, analytics rules, workbooks, dashboards, automation, and incident response playbooks within Microsoft Sentinel.
  • Experience supporting Microsoft Purview Data Loss Prevention, information protection, sensitivity labels, retention policies, insider risk, eDiscovery, or compliance-related security controls.
  • Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, MITRE ATT&CK, ISO 27001, or similar industry guidance.
  • Experience with threat hunting, detection engineering, malware analysis, phishing investigation, business email compromise response, or account compromise investigation.
  • Experience with cloud platforms, SaaS security, CASB capabilities, Azure security, Google Cloud Platform security, or multi-cloud security operations.
  • Experience working with ticketing systems, change management processes, vulnerability management platforms, and enterprise incident response workflows.
  • Strong written communication skills with the ability to produce clear technical documentation, investigation summaries, executive-level updates, and operational procedures.
  • Demonstrated commitment to continuous learning, process improvement, operational excellence, and maintaining awareness of evolving Microsoft security features and cyber threats.

Benefits & conditions

The firm offers a generous total compensation package with bonuses and raises awarded in recognition of individual merit-based performance. All full-time Business Services employees may participate in King & Spalding’s comprehensive benefit program including health and wellness plan, life and disability insurance, flexible spending accounts and a health savings account, a 401(k) plan, profit sharing plan, and a substantial Paid Time Off (PTO) program.

About the company

King & Spalding is a leading global law firm with a commitment to excellence, innovation, and the seamless delivery of legal services. We harness innovative technology and exceptional talent to meet the complex needs of our clients in a fast-paced and dynamic legal landscape., We are proud of our remarkably cohesive culture, which now encompasses more than 2,500 lawyers and business professionals worldwide. We seek to attract and develop the very best talent to work with us.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all