Senior Cybersecurity Engineer
Senior
Azure Ad / Entra Id
Cloud Platforms
Cyber Security
Cybersecurity Tools
Data Governance
Data Security
Defender For Cloud
Device Management
Engineer
Identity and Access Management
Incident Response
Information Security
InfoSec
Microsoft Defender Xdr
Microsoft Entra Id
Microsoft Intune
Microsoft Purview
Microsoft Sentinel
Mitre Att&ck
Mobile Device Management
Security Automation
Security Detections
Security Operations
SOAR
Job Description
Teleion Consulting is seeking a hands-on, client-facing Senior Cybersecurity Engineer to improve cloud security posture, strengthen incident response, and mature data security and zero trust across the Microsoft security ecosystem.
Responsibilities
- Configure, tune, and operate the Microsoft security stack in production client environments, including Microsoft Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
- Lead incident response for real security events, including account compromise, data exfiltration, insider risk, and BEC, covering containment, eradication, recovery, evidence preservation, and post-incident reporting.
- Coordinate with MXDR or managed SOC providers to maintain escalation quality, handoff standards, and case closure practices.
- Author and maintain KQL analytic rules and hunting queries in Microsoft Sentinel; map detections to MITRE ATT&CK, close coverage gaps, and tune for signal quality and ingestion cost.
- Develop SOAR playbooks to reduce false positives and automate analyst workflows.
- Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps, driving findings to closure.
- Implement and maintain sensitivity labels, auto-labeling at scale, Insider Risk Management, and eDiscovery support.
- Harden Azure and multi-cloud environments by remediating Defender for Cloud findings, improving secure score, and addressing cloud identity and entitlement risk.
- Advance zero trust maturity across identity, device, network, application, and data pillars using Conditional Access, PIM, device compliance, and least-privilege access patterns.
- Build PowerShell and Microsoft Graph API automations to scale security operations, reporting, and remediation.
- Design and run tabletop exercises to test and mature the client incident response capability.
Requirements
- 7+ years of security engineering or security operations experience in enterprise environments.
- Deep, production-configured hands-on experience across the full Microsoft security stack: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
- Demonstrated leadership handling real security incidents through the full lifecycle, including containment, eradication, recovery, and post-incident reporting.
- Strong KQL proficiency: analytic rule creation, hunting query development, tuning for cost and signal quality, and mapping to MITRE ATT&CK.
- Direct, demonstrable Microsoft Purview experience covering DLP policy design and tuning, sensitivity labels, Insider Risk Management, and eDiscovery.
- Experience hardening Azure environments by remediating Defender for Cloud findings, improving secure score, and addressing cloud identity and entitlement risk.
- Experience implementing zero trust controls across multiple pillars using Conditional Access and PIM and privileged access management.
- PowerShell and Microsoft Graph API proficiency for security automation.
- Experience coordinating with MXDR or managed SOC providers on escalation and case quality.
- Certifications preferred: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, or CISSP. Digital forensics experience in cloud and M365 environments is a plus.
Technologies
- Microsoft Sentinel
- Defender XDR
- Defender for Cloud
- Entra ID
- Intune
- Microsoft Purview
- KQL
- MITRE ATT&CK
- SOAR
- Microsoft Graph API
- PowerShell
- Conditional Access
- PIM
- Insider Risk Management
- eDiscovery
- DLP
- SharePoint
- OneDrive
- Teams
- Azure
- Microsoft security ecosystem
- MXDR
- Managed SOC providers
- Sensitivity labels
- Device compliance
- Least-privilege access patterns
- Tabletop exercises
Job Details
- Location: Seattle, WA (onsite)
- Compensation: USD 155,000 - 200,000 per year
- Employment type: contract
Benefits
- Full benefits
- PTO
- Holiday
- 401(k)