JOBSEARCHER

Senior Microsoft Security Engineer

ARCHIVED

We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.

Senior Microsoft Security Engineer Sentinel & Defender XDR Duration : 6 + months Location : Remote About the Role Senior Microsoft Security Engineer who knows Sentinel inside and out - and can carry that expertise across into Defender XDR. This is not a generalist role. The ideal candidate has deep, hands-on Sentinel experience, understands how Defender XDR maps to it functionally, and has ideally led or been a key contributor to a Sentinel-to-XDR migration in a production environment. You will be embedded with a client SOC team, owning detection engineering, platform configuration, and the technical work required to bridge two platforms without dropping coverage or continuity. If you have lived through a migration and know where the gaps are, this role was written for you. Key Responsibilities Microsoft Sentinel (Primary Platform)Design, configure, and optimize Microsoft Sentinel environments including data connectors, analytics rules, and workbooksBuild and maintain detection logic using UEBA, ML-based anomaly detection, and threat intelligence integrationsDevelop KQL queries and hunting workbooks for proactive threat identificationCreate and manage SOAR playbooks via Azure Logic Apps to automate SOC response workflowsContinuously tune detection rules and reduce false positive rates in partnership with the SOC teamDocument architecture decisions, runbooks, and operational procedures Microsoft Defender XDR (Secondary Platform)Map existing Sentinel analytics rules, KQL logic, and detection coverage to Defender XDR equivalentsConfigure and manage Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps within a unified XDR frameworkDefine and implement custom detection rules, incidents, and automated response actions within Defender XDRAssess capability gaps between the two platforms and develop mitigation or transition plansLeverage AI-native Defender XDR capabilities including automatic attack disruption and AI-assisted investigation Migration & Cross-Platform WorkLead or support Sentinel-to-XDR migration workstreams including data migration, rule translation, and platform configurationIdentify functional equivalencies and gaps between platforms and communicate tradeoffs clearly to SOC leadershipIntegrate both platforms with SIEM, SOAR, and CTI tooling as neededSupport Copilot for Security and AI-powered SOC automation use cases across both platforms Required Qualifications5+ years of hands-on experience with Microsoft Sentinel in an enterprise SOC environment - this is non-negotiableStrong proficiency in KQL and the ability to translate detection logic across platformsHands-on experience or equivalent training with Microsoft Defender for XDR, including deep familiarity with its sub-components: Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps (Note: Microsoft Defender XDR was released March 2026 - equivalent platform knowledge and migration readiness will be considered in place of tenure)Demonstrated experience with or direct involvement in a Sentinel-to-Defender XDR migration, or the ability to map Sentinel functionality to Defender XDR equivalents based on deep platform knowledge of bothSolid understanding of XDR concepts, cross-domain correlation, and automated incident responseDeep familiarity with the MITRE ATT&CK framework and its application to detection engineeringExperience with Azure Logic Apps, Power Automate, or similar automation platformsBackground in threat hunting, incident response, and SOC operations Preferred QualificationsMicrosoft Certified: Security Operations Analyst Associate (SC-200) - strongly preferredMicrosoft Certified: Cybersecurity Architect Expert (SC-100) - a plusBoth certifications held simultaneously - this will stand outHands-on experience with Copilot for Security and AI-assisted investigation features in Defender XDRPrior involvement in large-scale SIEM or XDR platform migrationsBackground in CTI integration and toolingExperience supporting global SOC teams across multiple regionsFamiliarity with SOAR platforms, CRIBL, or similar tools in the SOC ecosystemExposure to digital forensics or agentic AI workflows in a security operations context