Назад
Company hidden
9 дней назад

Senior Detection & Response Engineer (Microsoft Security)

142 900 - 207 200$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Detection & Response Engineer (Microsoft Security): Own detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 with an accent on Microsoft telemetry mapping, detection engineering, and API-driven investigation. Focus on tracking platform changes, optimizing KQL queries, automating investigative workflows, and translating ingestion, schema, licensing, and retention constraints into reliable customer coverage.

Location: Remote within the United States; headquarters in Herndon, Virginia. Candidates must be authorized to work in the United States.

Salary: $142,900–$207,200 USD base salary, plus bonus eligibility and equity. Target range: $160,000–$192,000 based on experience, skills, and market data.

Company

hirify.global provides transparent Managed Detection and Response services, combining security analysts, automation, and technology to help businesses address cybersecurity challenges.

What you will do

  • Own detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365.
  • Build and maintain a current map of Microsoft security signals, including ingestion lag, storage locations, licensing requirements, retention, and reliability.
  • Track Microsoft platform and schema changes, converting material changes into detection and coverage improvements.
  • Write, deploy, tune, and evaluate custom detections against Microsoft data sets and native detection capabilities.
  • Automate investigative workflows for SOC analysts through Graph, Defender, Sentinel, and Entra APIs.
  • Partner with Engineering on Microsoft integrations, API limits, throttling, ingestion, and schema mapping; advise SOC, customer success, sales, and customers.

Requirements

  • Deep hands-on knowledge of Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 security environments.
  • Ability to write, optimize, and debug complex KQL queries across Defender Advanced Hunting and Sentinel.
  • Experience with Graph, Graph Security, Defender, and Sentinel APIs, including authentication, permissions, versioning, and throttling.
  • Strong understanding of identity attacks, authentication flows, conditional access, OAuth consent, token theft and replay, hybrid identity, synchronization, and privileged role abuse.
  • Experience with Windows internals, command-line tooling, custom detections, Python, Sigma, and Anthropic tools such as Claude Code; familiarity with macOS and Linux is also expected.
  • 5+ years of experience in information technology or security operations, including substantial experience defending or operating Microsoft environments. Candidates must be authorized to work in the United States; immigration visa sponsorship is not available.

Nice to have

  • SC-200, AZ-500, or SC-300 certification.
  • Experience with AWS, GCP, other EDR platforms, or SIEM technologies.

Culture & Benefits

  • Remote work with flexibility in work location.
  • Unlimited PTO.
  • Up to 24 weeks of parental leave.
  • Health benefits, bonus eligibility, and equity.
  • Access to Microsoft telemetry from diverse customer environments and collaboration with analysts, data scientists, engineers, and responders.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →