Padmi

Senior Microsoft Security Engineer

Remote · United StatesPosted 1 month ago
CybersecurityUnspecified
Apply at 3B Staffing

Opens the source posting on 3bstaffing.com

Source description

About the role

View original

Senior Microsoft Security Engineer

Sentinel & Defender XDR

Duration : 6 + months

Location : Remote

About the Role

Senior Microsoft Security Engineer who knows Sentinel inside and out — and can carry that expertise across into Defender XDR. This is not a generalist role. The ideal candidate has deep, hands-on Sentinel experience, understands how Defender XDR maps to it functionally, and has ideally led or been a key contributor to a Sentinel-to-XDR migration in a production environment.

You will be embedded with a client SOC team, owning detection engineering, platform configuration, and the technical work required to bridge two platforms without dropping coverage or continuity. If you have lived through a migration and know where the gaps are, this role was written for you.

Key Responsibilities

Microsoft Sentinel (Primary Platform)

Design, configure, and optimize Microsoft Sentinel environments including data connectors, analytics rules, and workbooks

Build and maintain detection logic using UEBA, ML-based anomaly detection, and threat intelligence integrations

Develop KQL queries and hunting workbooks for proactive threat identification

Create and manage SOAR playbooks via Azure Logic Apps to automate SOC response workflows

Continuously tune detection rules and reduce false positive rates in partnership with the SOC team

Document architecture decisions, runbooks, and operational procedures

Microsoft Defender XDR (Secondary Platform)

Map existing Sentinel analytics rules, KQL logic, and detection coverage to Defender XDR equivalents

Configure and manage Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps within a unified XDR framework

Define and implement custom detection rules, incidents, and automated response actions within Defender XDR

Assess capability gaps between the two platforms and develop mitigation or transition plans

Leverage AI-native Defender XDR capabilities including automatic attack disruption and AI-assisted investigation

Migration & Cross-Platform Work

Lead or support Sentinel-to-XDR migration workstreams including data migration, rule translation, and platform configuration

Identify functional equivalencies and gaps between platforms and communicate tradeoffs clearly to SOC leadership

Integrate both platforms with SIEM, SOAR, and CTI tooling as needed

Support Copilot for Security and AI-powered SOC automation use cases across both platforms

Required Qualifications

5+ years of hands-on experience with Microsoft Sentinel in an enterprise SOC environment — this is non-negotiable

Strong proficiency in KQL and the ability to translate detection logic across platforms

Hands-on experience or equivalent training with Microsoft Defender for XDR, including deep familiarity with its sub-components: Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps (Note: Microsoft Defender XDR was released March 2026 — equivalent platform knowledge and migration readiness will be considered in place of tenure)

Demonstrated experience with or direct involvement in a Sentinel-to-Defender XDR migration, or the ability to map Sentinel functionality to Defender XDR equivalents based on deep platform knowledge of both

Solid understanding of XDR concepts, cross-domain correlation, and automated incident response

Deep familiarity with the MITRE ATT&CK framework and its application to detection engineering

Experience with Azure Logic Apps, Power Automate, or similar automation platforms

Background in threat hunting, incident response, and SOC operations

Preferred Qualifications

  • Microsoft Certified: Security Operations Analyst Associate (SC-200) — strongly preferred

  • Microsoft Certified: Cybersecurity Architect Expert (SC-100) — a plus

  • Both certifications held simultaneously — this will stand out

  • Hands-on experience with Copilot for Security and AI-assisted investigation features in Defender XDR

  • Prior involvement in large-scale SIEM or XDR platform migrations

  • Background in CTI integration and tooling

  • Experience supporting global SOC teams across multiple regions

  • Familiarity with SOAR platforms, CRIBL, or similar tools in the SOC ecosystem

  • Exposure to digital forensics or agentic AI workflows in a security operations context

One address, no account. We’ll tell you when matching roles go live.

More at 3B Staffing

Related open roles

View all roles