Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

Levelblue, LLC
United States
23 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$155,000.0 - $185,000.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Amazon Web Services Microsoft Azure Cloud Computing Cyber Security System Configuration Intrusion Detection and Prevention Network Security Microsoft Security Essentials Microsoft Office Parsing Query Optimization
+12 more
Kusto Query Language Security Information and Event Management EndPointSecurity Data Logging Microsoft Power Automate Power Platform Integration Multi-Cloud Firewalls (Computer Science) Build Management Microsoft Sentinel Splunk SentinelOne Expertise

Job description

Deliver engagements across a range of service lines. Lead SIEM design and implementation on greenfield SOC builds and brownfield optimization: data-source onboarding (e.g., telemetry analysis, ingestion design, parsing and normalization, custom connectors), analytics rules, hunting queries, automation rules and playbooks, workbooks, incident process alignment, and use-case documentation.

Design and build custom detection content aligned to the client’s threat profile and available telemetry.

Integrate and operationalize Microsoft Defender XDR.

Assess requirements and advise on best-practice implementation and configuration for Microsoft Purview, Entra ID, Defender for Cloud, Azure security, Copilot. Deliver guided implementation and hands-on configuration when required.

Microsoft Purview: you can discover client requirements, recommend a target configuration, and explain how to implement it (information protection, DLP, audit, or related controls as relevant). Hands-on build is desirable.

Build practical automation where it improves response quality: Sentinel automation rules, Logic Apps, and analyst response actions.

Produce client-ready design and build artifacts: for example, use case catalog, automation/playbook designs, implementation plans, gap analyses, tactical maturity roadmaps with executive summaries.

Facilitate workshops and discussion sessions; capture requirements, decisions, risks, and scope changes.

Requirements

Required

Senior consulting or professional-services delivery (not only an internal SOC or engineering seat): you have owned client workshops around business requirements and use case discovery, engagement scope, and signed-off deliverables.

Hands-on Microsoft Sentinel engineering in production, including analytic rule design and build, query tuning and optimization, false-positive reduction, and use-case operationalization.

Experience producing detection design records (AIR DDRs): our use case notes covering use case scenarios, data sources, KQL, tuning notes.

Hands-on Microsoft Defender XDR (at least Defender for Endpoint plus one of Identity / Office / Cloud Apps) in a detection or SOC-integration context.

Hands-on Microsoft Purview configuration in a security or compliance context connected to monitoring or control design.

Useful

Experience in any of the following is a plus and may be used on engagements; it does not replace SIEM engineering or Microsoft security delivery.

Firewall / network security configuration reviews (policy quality, logging to SIEM, segmentation relevant to detections).

Active Directory security reviews (beyond detections): privileged access, delegation, hardening, hybrid identity.

Azure security reviews (beyond Defender for Cloud / Sentinel): landing-zone and control-plane hygiene.

AWS security reviews or multi-cloud posture work.

Splunk or SentinelOne (working knowledge).

Broader control reviews that feed a security operations or threat detection and response roadmap.

Certifications (desirable)

Most relevant: SC-200; SC-500 (AZ-500)

Also useful: SC-100, SC-300, SC-400; Splunk ES Admin or Splunk Architect; GIAC detection/IR (e.g. GCIA, GCIH); CISSP

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Loading talks and stories from around this role…