24 часа назад
Microsoft Security Automation & Incident Response Engineer - Contract Position (Microsoft Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Microsoft Security Automation & Incident Response Engineer - Contract Position (Microsoft Security): Optimizing Microsoft security operations through Sentinel and Defender integrations, detection engineering, and incident response automation with an accent on reducing manual analyst workload, false positives, and response times. Focus on designing KQL-based detections, Logic Apps and SOAR workflows, investigation playbooks, and operational runbooks.
Location: United States; remote
Employment type: Contract; duration: 3–4 months
Company
develops security and digital forensics solutions and is expanding the maturity and efficiency of its security operations program.
What you will do
- Analyze security alert triage and incident response processes, identify bottlenecks, and reduce manual analyst effort.
- Tune Microsoft Sentinel analytics rules, reduce false positives, and create advanced correlation and threat-hunting content.
- Design automation for alert enrichment, incident routing, ticket creation, escalations, investigations, and standard response actions.
- Integrate and optimize Microsoft Sentinel, Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Entra ID, Zscaler telemetry, and ITSM platforms.
- Improve incident response processes, investigation playbooks, response automation, operational runbooks, and documentation.
Requirements
- Must be authorized to work in the United States.
- 5+ years of experience in security operations, detection engineering, or incident response.
- Strong experience with Microsoft Sentinel and the Microsoft Defender suite.
- Advanced KQL, Logic Apps, SOAR automation, and SIEM engineering skills.
- Experience optimizing security operations workflows.
Nice to have
- Microsoft Security certifications.
- Threat hunting and detection engineering experience.
- Experience integrating third-party security telemetry.
- Exposure to Purview and DLP technologies.
Culture & Benefits
- Remote contract engagement lasting 3–4 months.
- Emphasis on care, accountability, dedication, integrity, empathy, and respect.
- Focus on continuous learning, innovation, and building a diverse and inclusive workforce.
- Background check required as a condition of employment.
Hiring process
- Recruitment is designed to support an inclusive and accessible process.
- Offers are contingent on satisfactory completion of a background check.
- US applicants undergo employment authorization verification through E-Verify.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Senior Information Security Engineer (Cybersecurity)
5 дней назад
Senior Security Analyst (Cybersecurity)
50 000 - 60 000GBP
6 дней назад
Security Operations Lead (AI)
180 000 - 210 000$
7 дней назад
SOC Analyst (Cybersecurity)
6 дней назад
Staff Security Engineer - SecOps & Threats
231 089 - 265 931$
5 дней назад
Staff Security Engineer (AI)
212 000 - 265 000$