9 дней назад
Senior Detection & Response Engineer (Microsoft Security)
142 900 - 207 200$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Detection & Response Engineer (Microsoft Security): Own detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 with an accent on Microsoft telemetry mapping, detection engineering, and API-driven investigation. Focus on tracking platform changes, optimizing KQL queries, automating investigative workflows, and translating ingestion, schema, licensing, and retention constraints into reliable customer coverage.
Location: Remote within the United States; headquarters in Herndon, Virginia. Candidates must be authorized to work in the United States.
Salary: $142,900–$207,200 USD base salary, plus bonus eligibility and equity. Target range: $160,000–$192,000 based on experience, skills, and market data.
Company
provides transparent Managed Detection and Response services, combining security analysts, automation, and technology to help businesses address cybersecurity challenges.
What you will do
- Own detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365.
- Build and maintain a current map of Microsoft security signals, including ingestion lag, storage locations, licensing requirements, retention, and reliability.
- Track Microsoft platform and schema changes, converting material changes into detection and coverage improvements.
- Write, deploy, tune, and evaluate custom detections against Microsoft data sets and native detection capabilities.
- Automate investigative workflows for SOC analysts through Graph, Defender, Sentinel, and Entra APIs.
- Partner with Engineering on Microsoft integrations, API limits, throttling, ingestion, and schema mapping; advise SOC, customer success, sales, and customers.
Requirements
- Deep hands-on knowledge of Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365 security environments.
- Ability to write, optimize, and debug complex KQL queries across Defender Advanced Hunting and Sentinel.
- Experience with Graph, Graph Security, Defender, and Sentinel APIs, including authentication, permissions, versioning, and throttling.
- Strong understanding of identity attacks, authentication flows, conditional access, OAuth consent, token theft and replay, hybrid identity, synchronization, and privileged role abuse.
- Experience with Windows internals, command-line tooling, custom detections, Python, Sigma, and Anthropic tools such as Claude Code; familiarity with macOS and Linux is also expected.
- 5+ years of experience in information technology or security operations, including substantial experience defending or operating Microsoft environments. Candidates must be authorized to work in the United States; immigration visa sponsorship is not available.
Nice to have
- SC-200, AZ-500, or SC-300 certification.
- Experience with AWS, GCP, other EDR platforms, or SIEM technologies.
Culture & Benefits
- Remote work with flexibility in work location.
- Unlimited PTO.
- Up to 24 weeks of parental leave.
- Health benefits, bonus eligibility, and equity.
- Access to Microsoft telemetry from diverse customer environments and collaboration with analysts, data scientists, engineers, and responders.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
14 дней назад
Senior Tactical Response Analyst (Cybersecurity)
125 000 - 135 000$
Writer
12 дней назад
Staff Detection and Response Engineer (AI Security)
146 000 - 240 000$
10 дней назад
Cyber Security Analyst, Senior (High Level Clearance Required)
108 476 - 184 409$
13 дней назад
Senior Detection Engineering & Threat Hunting Analyst (Cybersecurity)
150 000 - 170 000$
Roblox
10 дней назад
Senior Detection and Response Engineer
196 750 - 243 290$
9 дней назад