Job Description
Job Description: Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST. This position will help strengthen the cloud security posture, mature incident response capabilities, and advance data security and zero-trust initiatives. Responsibilities Cloud security: - Harden Azure and multi-cloud environments against recognized benchmarks and cloud security posture findings - Remediate Defender for Cloud findings and drive measurable secure score improvement - Implement workload protection, configuration baselines, and infrastructure-as-code security checks - Address cloud identity and entitlement risk, including overprivileged roles, service principals, and standing access Incident response: - Enhance and operationalize incident response playbooks aligned to NIST SP 800-61 - Lead and support investigations across cloud, identity, endpoint, email, and SaaS, including account compromise, data exfiltration, insider risk, and business email compromise - Perform containment, eradication, recovery, evidence preservation, and post-incident reporting - Coordinate with the managed detection and response provider on escalation quality, handoff, and case closure - Design and facilitate tabletop exercises and translate findings into control improvements SIEM optimization and detection engineering: - Tune Microsoft Sentinel for signal quality and cost efficiency, including connector selection, ingestion tiering, and table-level retention decisions - Author and maintain analytic rules and hunting queries in KQL - Map detection coverage to MITRE ATT&CK and close identified gaps - Reduce false positive volume and improve alert enrichment and automation through SOAR playbooks Data security and DLP: - Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps - Implement sensitivity labels, auto-labeling, and data classification at scale - Operate Insider Risk Management and support eDiscovery and investigative requests - Drive DLP findings to closure through policy change, access revocation, or corrective action, not just alerting Zero trust: - Advance zero trust maturity across identity, device, network, application, and data pillars - Implement and refine conditional access, privileged identity management, device compliance, and least privilege access models - Support segmentation and egress control initiatives Required Qualifications - 7+ years in security engineering or security operations - Deep hands-on Microsoft security stack experience: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune - Direct, demonstrable Microsoft Purview experience across DLP, sensitivity labels, and Insider Risk Management - Strong KQL authoring ability, including detection development and investigative hunting - Demonstrated incident response leadership on real incidents, not tabletop only - Azure cloud security depth, including identity, networking, and workload protection - PowerShell and Microsoft Graph API automation - Clear written communication for both technical peers and executive audiences Preferred - Experience in a lean security team where the role spans engineering and operations - Familiarity with Palo Alto Networks, Tanium, and CASB or SSPM platforms - Digital forensics experience, including cloud and M365 artifact analysis - Experience working alongside an MXDR or managed SOC provider - Certifications: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, CISSP Pay Range: $85.00 - $95.00 per hour, depending upon experience. Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.