> Markdown version of [/jobs/ext/514952-cyber-automation](https://www.wearedevelopers.com/jobs/ext/514952-cyber-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Automation - **Company:** Capgemini - **Location:** New York, NY, United States - **Salary:** $67,744.0 - $147,804.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Microsoft Azure, Cloud Computing, Cloud Computing Security, Software Documentation, Cyber Security, Intrusion Detection and Prevention, Network Security, Log Analysis, Microsoft Security Essentials, Windows PowerShell, Azure Active Directory, Kusto Query Language, Security Information and Event Management, Software Vulnerability Management, EndPointSecurity, Information Security Management System, Microsoft Power Automate, Microsoft InTune, Patch Management, Microsoft Sentinel, Azure Resource Manager, Servicenow - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9420332b3cd5a35c ## About the Role Do you have experience in Security compliance frameworks implementation?, Do you have a Bachelor's degree?, Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field. Experience: * 3+ years of experience in cybersecurity or SOC operations. * 1+ years working with Microsoft Sentinel, Defender for Cloud, and Defender for Endpoint. * Experience in Azure Government and Microsoft 365 GCC-High environments. * Practical experience in log analysis, incident response, and SIEM management. * Familiarity with compliance frameworks including CMMC Level 2, NIST SP 800-171, and FedRAMP High. Technical Skills: * Proficiency with KQL (Kusto Query Language) and Sentinel analytics. * Strong understanding of network security, endpoint protection, and cloud security monitoring. * Experience integrating alerts and workflows into ServiceNow or similar ITSM tools. * Knowledge of Active Directory, Entra ID (Azure AD), and conditional access policies. Soft Skills: Excellent analytical, investigative, and communication skills; strong documentation discipline and attention to detail; U.S. Citizenship required (for access to GCC-High and Azure Government environments). Desired Qualifications * Microsoft Certified: Cybersecurity Architect Expert or Azure Administrator Associate. * Security+ (CompTIA), Microsoft Certified: Security Operations Analyst Associate, or equivalent. * GIAC (GCIH, GCIA) or CISSP certification. * Experience working with Defender for Identity, Purview, and Conditional Access policy design. * Background in automation (Logic Apps, Power Automate, or PowerShell). * Prior SOC experience supporting Federal or Defense Industrial Base (DIB) clients. * Familiarity with incident ticket workflows, evidence collection, and reporting for CMMC Level 2 audits. ## Description Security Monitoring & Incident Response * Monitor alerts and security events generated from Microsoft Sentinel, Defender for Cloud, Defender for Endpoint, Defender for Identity, and other SOC tools. * Perform initial triage, correlation, and investigation of security incidents to determine severity and impact. * Escalate confirmed incidents and support containment, eradication, and recovery actions. * Document incident response steps, root-cause analysis, and lessons learned. * Maintain 24×7 situational awareness coverage through rotating on-call or shift responsibilities as required. Threat Detection & Analysis * Conduct proactive threat hunting using Sentinel analytics, KQL queries, and custom detection rules. * Analyze logs and telemetry from endpoints, firewalls, Azure resources, and AVD hosts for anomalous activity. * Identify potential indicators of compromise (IOCs) and emerging threats within the Azure Government and M365 GCC-High ecosystems. * Recommend tuning improvements to detections and correlation rules to reduce false positives. Vulnerability & Patch Management * Support regular vulnerability scans, review results, and track remediation activities. * Collaborate with infrastructure and Intune teams to validate patch compliance across AVD and Windows 365 assets. * Monitor Defender Vulnerability Management dashboards and report high-risk exposures to leadership. * Assist in maintaining asset inventories, vulnerability baselines, and patch metrics. Compliance, Audit, & CMMC Level 2 Support * Support ongoing CMMC Level 2 and NIST SP 800-171 compliance efforts through control monitoring, evidence collection, and reporting. * Maintain and update security-related documentation, including incident response plans, SIEM configurations, and POA&M items. * Provide input to the System Security Plan (SSP) on monitoring and incident response controls. * Participate in internal audits, tabletop exercises, and compliance reviews to ensure readiness. Tool Administration & Optimization * Administer SOC and security tools such as Microsoft Sentinel, Defender for Cloud, and Defender for Endpoint. * Develop custom Sentinel workbooks, dashboards, and KQL queries for enhanced visibility. * Integrate alerts with ServiceNow for incident and change management workflows. * Support automation initiatives using Logic Apps, Playbooks, or PowerShell to streamline incident response. Reporting & Continuous Improvement * Produce daily and weekly SOC summaries, incident metrics, and trend analyses. * Deliver executive-level reports summarizing threat activity, vulnerabilities, and remediation progress. * Recommend improvements to SOC processes, escalation procedures, and documentation standards. * Stay current on evolving threats, tools, and Microsoft security technologies applicable to Azure Government environments. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)