Security Engineer (Remote)
Overview
In this role you design, implement, and continuously improve security controls across cloud, identity, endpoint, email, network, data, and hybrid infrastructure. You will translate requirements and threat scenarios into dependable configurations, detections, automations, investigations, and documented procedures. You’ll collaborate with Infrastructure, Network, Cloud, IAM, Microsoft 365, Application, Service Desk, Legal, Privacy, Audit, and third parties to reduce risk and improve security operations. Expect to own tasks from intake through validation, evidence collection, and closure, with a focus on measurable impact. This is a hands-on role at scale, emphasizing Zero Trust principles, aud
ResponsibilitiesDesign, implement, and operate security controls across multiple domains (cloud, identity, endpoint, email, network, data, hybrid environments)Engineer and tune detections, automations, and investigations; maintain operational procedures and runbooksPerform security design reviews and provide consultation for cloud, network, identity, endpoint, messaging, and data protection initiativesDrive incident triage, containment, and root-cause analysis; manage evidence and follow-up actionsMaintain security platform configurations and documentation; ensure change records and audit readinessCoordinate with platform owners on endpoint coverage, cloud posture, vulnerability exposure, and telemetry gapsDevelop and maintain SIEM/SOX content, including queries, dashboards, playbooks, and automationParticipate in on-call rotations and after-hours production support as requiredSupport governance, risk, and compliance activities with technical evidence and remediation updates
Key requirementsHands-on experience with enterprise SIEM and security analyticsExperience investigating security events across two or more domainsWorking knowledge of Microsoft cloud/security tech (Sentinel, Defender XDR, Entra ID, Azure, Microsoft 365, Purview)Knowledge of enterprise network security concepts (firewalls, segmentation, VPNs, DNS, TLS, routing, proxies)Scripting or automation ability (PowerShell, KQL, Python, APIs, JSON)Experience with incident, request, problem, and change-management practicesUnderstanding of NIST principles and regulated environments (PCI DSS, SOX, privacy)Ability to communicate risk and findings to technical and non-technical audiencesclear communicationdisciplined ownershiptechnical curiosityMicrosoft SentinelMicrosoft Defender XDRCrowdStrike Falcon