> Markdown version of [/jobs/ext/3329212-microsoft-security-engineer](https://www.wearedevelopers.com/jobs/ext/3329212-microsoft-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Microsoft Security Engineer - **Company:** King & Spalding LLP. - **Location:** Atlanta, GA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Microsoft Antivirus, Authentication Protocols, Microsoft Azure, Microsoft Online Services, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, System Configuration, Information Leak Prevention, Data Security, Domain Name System (DNS), Identity and Access Management, Issue Tracking Systems, Intrusion Detection and Prevention, Log Analysis, Microsoft Security Essentials, Microsoft Office, Microsoft Software, Networking Basics, Performance Tuning, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Cloud Services, Anti-Phishing, Kusto Query Language, Runbook, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Microsoft Power Automate, Facebook Flow, Mitre Att&ck, Multi-Cloud, Malware, Cyber Threat Analysis, Microsoft InTune, Azure Security Center, Microsoft Fabric, Information Technology, Cybercrime, Microsoft Sentinel, CIS Benchmarks - **Published:** September 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4c0dd32da00fdfc3 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent professional experience may be considered in lieu of a degree. * Minimum of 3-5 years of experience in information security, security engineering, security operations, cloud security, identity security, endpoint security, or a related IT security role. * Hands-on experience administering or supporting Microsoft security technologies, such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, Microsoft 365 security, or Azure security services. * Strong understanding of cybersecurity principles, including defense-in-depth, least privilege, identity and access management, endpoint protection, email security, cloud security, vulnerability management, logging, monitoring, and incident response. * Experience configuring and maintaining security policies, conditional access rules, authentication controls, endpoint security baselines, data protection policies, and alerting rules. * Ability to investigate security alerts, analyze logs and telemetry, identify root cause, document findings, and recommend remediation actions. * Working knowledge of enterprise infrastructure, including Windows, Active Directory, Azure, Microsoft 365, networking fundamentals, DNS, email flow, authentication protocols, and cloud services. * Experience using scripting, query, or automation tools such as PowerShell, Kusto Query Language (KQL), Microsoft Graph, Logic Apps, or similar technologies. * Ability to communicate technical concepts clearly to security teams, IT stakeholders, business partners, leadership, and non-technical audiences. * Strong analytical, troubleshooting, documentation, collaboration, and time-management skills. * Ability to work independently and as part of a cross-functional team in a fast-paced enterprise environment. * Willingness to participate in incident response, maintenance windows, and on-call rotations when required., * Microsoft security certifications such as SC-200, SC-300, SC-400, AZ-500, MS-102, or equivalent cloud/security certifications. * Experience with Microsoft Defender XDR incident queues, Advanced Hunting, secure score improvement, attack simulation, endpoint detection and response, email protection, identity protection, or cloud app security. * Experience building, tuning, or maintaining SIEM use cases, analytics rules, workbooks, dashboards, automation, and incident response playbooks within Microsoft Sentinel. * Experience supporting Microsoft Purview Data Loss Prevention, information protection, sensitivity labels, retention policies, insider risk, eDiscovery, or compliance-related security controls. * Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, MITRE ATT&CK, ISO 27001, or similar industry guidance. * Experience with threat hunting, detection engineering, malware analysis, phishing investigation, business email compromise response, or account compromise investigation. * Experience with cloud platforms, SaaS security, CASB capabilities, Azure security, Google Cloud Platform security, or multi-cloud security operations. * Experience working with ticketing systems, change management processes, vulnerability management platforms, and enterprise incident response workflows. * Strong written communication skills with the ability to produce clear technical documentation, investigation summaries, executive-level updates, and operational procedures. * Demonstrated commitment to continuous learning, process improvement, operational excellence, and maintaining awareness of evolving Microsoft security features and cyber threats. ## Description The Microsoft Security Engineer is responsible for designing, implementing, configuring, and maintaining enterprise security capabilities across the Microsoft security ecosystem. This role supports identity protection, endpoint security, cloud security, email security, data protection, threat detection, and security operations by using Microsoft technologies such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, and related Microsoft 365 security services., * Administer, configure, and optimize Microsoft security platforms, including Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and related security services. * Design and implement security policies, standards, controls, and configurations that reduce risk and improve the organization's overall security posture. * Manage identity and access security controls, including creating conditional access policies. * Support endpoint, email, identity, cloud application, and data protection security operations through effective security policies. * Develop and maintain detection logic, alert rules, automation, playbooks, dashboards, and operational procedures within Microsoft Sentinel and Microsoft Defender. * Partner with threat response, detection engineering, infrastructure, endpoint, messaging, and compliance teams to improve prevention, detection, response, and recovery capabilities. * Perform security health checks, configuration reviews, control validation, and hardening activities across Microsoft 365, Azure, endpoint, identity, email, and SaaS environments. * Support investigations associated with phishing, malware, account compromise, suspicious authentication, data exposure, endpoint threats, and cloud-based threats. * Analyze logs, alerts, telemetry, indicators of compromise, and threat intelligence to identify suspicious behavior and partner with detection engineering teams create proactive alerts. * Stay current on Microsoft security capabilities, emerging cyber threats, industry best practices, and regulatory or compliance requirements affecting enterprise security operations. * Participate in change management, security projects, audit support, vulnerability remediation, and after-hours incident response or on-call coverage as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)