Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
Deliver engagements across a range of service lines. Lead SIEM design and implementation on greenfield SOC builds and brownfield optimization: data-source onboarding (e.g., telemetry analysis, ingestion design, parsing and normalization, custom connectors), analytics rules, hunting queries, automation rules and playbooks, workbooks, incident process alignment, and use-case documentation.
Design and build custom detection content aligned to the client’s threat profile and available telemetry.
Integrate and operationalize Microsoft Defender XDR.
Assess requirements and advise on best-practice implementation and configuration for Microsoft Purview, Entra ID, Defender for Cloud, Azure security, Copilot. Deliver guided implementation and hands-on configuration when required.
Microsoft Purview: you can discover client requirements, recommend a target configuration, and explain how to implement it (information protection, DLP, audit, or related controls as relevant). Hands-on build is desirable.
Build practical automation where it improves response quality: Sentinel automation rules, Logic Apps, and analyst response actions.
Produce client-ready design and build artifacts: for example, use case catalog, automation/playbook designs, implementation plans, gap analyses, tactical maturity roadmaps with executive summaries.
Facilitate workshops and discussion sessions; capture requirements, decisions, risks, and scope changes.
Requirements
Required
Senior consulting or professional-services delivery (not only an internal SOC or engineering seat): you have owned client workshops around business requirements and use case discovery, engagement scope, and signed-off deliverables.
Hands-on Microsoft Sentinel engineering in production, including analytic rule design and build, query tuning and optimization, false-positive reduction, and use-case operationalization.
Experience producing detection design records (AIR DDRs): our use case notes covering use case scenarios, data sources, KQL, tuning notes.
Hands-on Microsoft Defender XDR (at least Defender for Endpoint plus one of Identity / Office / Cloud Apps) in a detection or SOC-integration context.
Hands-on Microsoft Purview configuration in a security or compliance context connected to monitoring or control design.
Useful
Experience in any of the following is a plus and may be used on engagements; it does not replace SIEM engineering or Microsoft security delivery.
Firewall / network security configuration reviews (policy quality, logging to SIEM, segmentation relevant to detections).
Active Directory security reviews (beyond detections): privileged access, delegation, hardening, hybrid identity.
Azure security reviews (beyond Defender for Cloud / Sentinel): landing-zone and control-plane hygiene.
AWS security reviews or multi-cloud posture work.
Splunk or SentinelOne (working knowledge).
Broader control reviews that feed a security operations or threat detection and response roadmap.
Certifications (desirable)
Most relevant: SC-200; SC-500 (AZ-500)
Also useful: SC-100, SC-300, SC-400; Splunk ES Admin or Splunk Architect; GIAC detection/IR (e.g. GCIA, GCIH); CISSP
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…