Microsoft Defender & Sentinel Administrator
SilverXis, Inc.
United States
6 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Apple Mac Systems
Microsoft Azure
Cloud Computing
Cloud Computing Security
Cyber Security
Linux
Intrusion Detection and Prevention
Log Analysis
Microsoft Office
Azure Active Directory
Kusto Query Language
+9 more
Software Vulnerability Management
EndPointSecurity
Mitre Att&ck
Mttr
Microsoft InTune
Cybercrime
Microsoft Sentinel
CIS Benchmarks
Multiplatform
Job description
Microsoft Defender Administration
- Threat Protection: Administer and optimize Microsoft Defender XDR components, including Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps.
- Vulnerability Management: Monitor endpoint health, assess software vulnerabilities, and enforce security baselines across multi-platform endpoints (Windows, macOS, Linux, mobile).
- Incident Triage: Investigate high-priority security alerts, analyze threat vectors, and execute containment or remediation steps.
Microsoft Sentinel Operations
- Workspace Management: Administer Microsoft Sentinel workspaces, configure data connectors, and ensure the seamless ingestion of logs from Azure, M365, and third-party sources.
- Detection Engineering: Create, test, and tune analytics rules, hunting queries, and parsers using Kusto Query Language (KQL) mapped to the MITRE ATT&CK framework.
- Threat Proactivity: Conduct proactive threat hunting to uncover hidden anomalous activity across identity, cloud, and network telemetry.
Automation & Orchestration
- Playbook Development: Design, build, and troubleshoot automation rules and security playbooks using Azure Logic Apps.
- Workflow Efficiency: Automate incident enrichment, triage notifications, ticket creation, and standard containment responses to reduce Mean Time to Respond (MTTR).
Requirements
- Experience: 5+ years of hands-on experience in cybersecurity administration, security operations (SOC), or cloud infrastructure security.
-
Technical Expertise:
- Deep knowledge of Microsoft Defender security suite and Microsoft Sentinel.
- Proficiency in Kusto Query Language (KQL) for log analysis and threat hunting.
- Experience building Azure Logic Apps and security playbooks.
- Familiarity with Microsoft Entra ID (Azure AD) and Microsoft Intune
- Must be familiar with Authorization protocol, MFA and conduction access.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…