CybersecurityJobs.io
← Back to all jobs

Job Description

Teleion Consulting is seeking a hands-on, client-facing Senior Cybersecurity Engineer to improve cloud security posture, strengthen incident response, and mature data security and zero trust across the Microsoft security ecosystem.

Responsibilities

  • Configure, tune, and operate the Microsoft security stack in production client environments, including Microsoft Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
  • Lead incident response for real security events, including account compromise, data exfiltration, insider risk, and BEC, covering containment, eradication, recovery, evidence preservation, and post-incident reporting.
  • Coordinate with MXDR or managed SOC providers to maintain escalation quality, handoff standards, and case closure practices.
  • Author and maintain KQL analytic rules and hunting queries in Microsoft Sentinel; map detections to MITRE ATT&CK, close coverage gaps, and tune for signal quality and ingestion cost.
  • Develop SOAR playbooks to reduce false positives and automate analyst workflows.
  • Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps, driving findings to closure.
  • Implement and maintain sensitivity labels, auto-labeling at scale, Insider Risk Management, and eDiscovery support.
  • Harden Azure and multi-cloud environments by remediating Defender for Cloud findings, improving secure score, and addressing cloud identity and entitlement risk.
  • Advance zero trust maturity across identity, device, network, application, and data pillars using Conditional Access, PIM, device compliance, and least-privilege access patterns.
  • Build PowerShell and Microsoft Graph API automations to scale security operations, reporting, and remediation.
  • Design and run tabletop exercises to test and mature the client incident response capability.

Requirements

  • 7+ years of security engineering or security operations experience in enterprise environments.
  • Deep, production-configured hands-on experience across the full Microsoft security stack: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
  • Demonstrated leadership handling real security incidents through the full lifecycle, including containment, eradication, recovery, and post-incident reporting.
  • Strong KQL proficiency: analytic rule creation, hunting query development, tuning for cost and signal quality, and mapping to MITRE ATT&CK.
  • Direct, demonstrable Microsoft Purview experience covering DLP policy design and tuning, sensitivity labels, Insider Risk Management, and eDiscovery.
  • Experience hardening Azure environments by remediating Defender for Cloud findings, improving secure score, and addressing cloud identity and entitlement risk.
  • Experience implementing zero trust controls across multiple pillars using Conditional Access and PIM and privileged access management.
  • PowerShell and Microsoft Graph API proficiency for security automation.
  • Experience coordinating with MXDR or managed SOC providers on escalation and case quality.
  • Certifications preferred: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, or CISSP. Digital forensics experience in cloud and M365 environments is a plus.

Technologies

  • Microsoft Sentinel
  • Defender XDR
  • Defender for Cloud
  • Entra ID
  • Intune
  • Microsoft Purview
  • KQL
  • MITRE ATT&CK
  • SOAR
  • Microsoft Graph API
  • PowerShell
  • Conditional Access
  • PIM
  • Insider Risk Management
  • eDiscovery
  • DLP
  • SharePoint
  • OneDrive
  • Teams
  • Azure
  • Microsoft security ecosystem
  • MXDR
  • Managed SOC providers
  • Sensitivity labels
  • Device compliance
  • Least-privilege access patterns
  • Tabletop exercises

Job Details

  • Location: Seattle, WA (onsite)
  • Compensation: USD 155,000 - 200,000 per year
  • Employment type: contract

Benefits

  • Full benefits
  • PTO
  • Holiday
  • 401(k)

Similar Jobs