> Markdown version of [/jobs/ext/612581-fedramp-security-architect](https://www.wearedevelopers.com/jobs/ext/612581-fedramp-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # FedRAMP Security Architect - **Company:** Revel IT - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Proxy Servers, Microsoft Azure, Big Data, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Data Mapping, DevOps, Identity and Access Management, Information Lifecycle Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Parsing, Kusto Query Language, Security Information and Event Management, Data Logging, Data Ingestion, Microsoft Power Automate, Mitre Att&ck, Firewalls (Computer Science), Information Technology, Cybercrime, Microsoft Sentinel - **Published:** June 18, 2026 - **Apply:** https://www.techlifecolumbus.com/job/37124-fedramp-security-architect-remote-1059054-remote-usa/ ## About the Role * Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field * Equivalent combination of education and related experience * 5 years of experience in a Security Operations Center (SOC), Incident Response, Azure Cloud Security * Extensive SOC experience (L3/Senior/Principal level), serving as an escalation point for complex and high-severity incidents * Expert-level proficiency in Microsoft Sentinel (Azure SIEM), with deep expertise in log ingestion, integration, data lifecycle management, and incident investigation. * Strong expertise in log normalization, parsing, and data quality management, ensuring high-fidelity detections * Demonstrated ability to optimize SIEM performance, reducing noise while improving detection accuracy and coverage * Experience with automation and orchestration, including Sentinel playbooks and Logic Apps to enhance response efficiency * Deep experience in detection engineering, including designing, implementing, and tuning analytics aligned to MITRE ATT&CK * Advanced KQL expertise for large-scale data analysis, threat hunting, and detection development * Expertise in managing and utilizing a wide range of security tools, including Next Generation Firewall, IDS/IPS, EDR, AV, MS Defender Suite, Internet Proxy, other Cloud Security Tools, etc. * Strong knowledge of cloud and enterprise security technologies, including Microsoft Defender suite, identity security (Entra ID), EDR/XDR, firewalls, and cloud-native controls * Proven leadership in threat hunting and incident response, including RCA and continuous improvement of detection and response capabilities * Strong communication and stakeholder engagement skills, with the ability to influence technical and non-technical teams * Demonstrated mentorship of SOC analysts, driving operational maturity * Relevant certifications (SC-200, AZ-500, CySA+) preferred * Strong analytical and problem-solving skills, with the ability to operate effectively in a fast-paced environment * Commitment to continuous learning and staying current with evolving threats and technologies ## Description The primary responsibility will be managing and administering security tools - particularly MS Sentinel SIEM, which will make up a significant portion of the role - along with other duties outlined in the JD., * As a Senior Cybersecurity Operations Engineer, this resource will play a key role in leading security operations by leveraging Microsoft Sentinel as the central platform for detection, investigation, and response. * This resource will act as a lead for high-severity incidents, driving end-to-end triage, root cause analysis, and continuous improvement of detection capabilities. * You will design and optimize detection use cases, lead proactive threat hunting initiatives, and enhance automation to improve response efficiency. * Lead triage and response for incidents and leading incident response efforts and coordination across technical teams during major security events * Drive root cause analysis (RCA) for critical incidents and translate findings into improvements across detection engineering, logging strategy, and response workflows * Own the log onboarding strategy and architecture for Microsoft Sentinel, ensuring comprehensive visibility across cloud, on-premises, and integrations * Lead integration of new data sources into Sentinel, including defining onboarding standards, data mapping, normalization, and validation of log quality * Identify and remediate logging gaps across the enterprise, partnering with engineering, cloud, and application teams to improve telemetry coverage * Establish and enforce best practices for log ingestion, retention, and cost optimization within Azure Sentinel * Design, develop, and continuously improve detection use cases and analytics rules, aligned to MITRE ATT&CK and evolving threat landscape * Own SIEM tuning strategy, reducing noise while ensuring high-confidence, high-fidelity detections * Lead proactive threat hunting initiatives using KQL and integrated threat intelligence, uncovering advanced or previously undetected threats * Architect and oversee Sentinel automation (playbooks, Logic Apps) to improve response efficiency and consistency * Develop and maintain advanced dashboards, workbooks, and reporting to provide actionable security insights to stakeholders * Mentor and coach junior and mid-level SOC analysts, setting standards for investigations, KQL usage, and operational excellence * Collaborate cross-functionally with cloud, DevOps, identity, and infrastructure teams to embed security visibility and detection into system design * Own and continuously improve SOC documentation, including SOPs, playbooks, and onboarding standards for new data sources and detections ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)