Source description
About the role
Senior Microsoft Security Engineer
Sentinel & Defender XDR
Duration : 6 + months
Location : Remote
About the Role
Senior Microsoft Security Engineer who knows Sentinel inside and out — and can carry that expertise across into Defender XDR. This is not a generalist role. The ideal candidate has deep, hands-on Sentinel experience, understands how Defender XDR maps to it functionally, and has ideally led or been a key contributor to a Sentinel-to-XDR migration in a production environment.
You will be embedded with a client SOC team, owning detection engineering, platform configuration, and the technical work required to bridge two platforms without dropping coverage or continuity. If you have lived through a migration and know where the gaps are, this role was written for you.
Key Responsibilities
Microsoft Sentinel (Primary Platform)
Design, configure, and optimize Microsoft Sentinel environments including data connectors, analytics rules, and workbooks
Build and maintain detection logic using UEBA, ML-based anomaly detection, and threat intelligence integrations
Develop KQL queries and hunting workbooks for proactive threat identification
Create and manage SOAR playbooks via Azure Logic Apps to automate SOC response workflows
Continuously tune detection rules and reduce false positive rates in partnership with the SOC team
Document architecture decisions, runbooks, and operational procedures
Microsoft Defender XDR (Secondary Platform)
Map existing Sentinel analytics rules, KQL logic, and detection coverage to Defender XDR equivalents
Configure and manage Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps within a unified XDR framework
Define and implement custom detection rules, incidents, and automated response actions within Defender XDR
Assess capability gaps between the two platforms and develop mitigation or transition plans
Leverage AI-native Defender XDR capabilities including automatic attack disruption and AI-assisted investigation
Migration & Cross-Platform Work
Lead or support Sentinel-to-XDR migration workstreams including data migration, rule translation, and platform configuration
Identify functional equivalencies and gaps between platforms and communicate tradeoffs clearly to SOC leadership
Integrate both platforms with SIEM, SOAR, and CTI tooling as needed
Support Copilot for Security and AI-powered SOC automation use cases across both platforms
Required Qualifications
5+ years of hands-on experience with Microsoft Sentinel in an enterprise SOC environment — this is non-negotiable
Strong proficiency in KQL and the ability to translate detection logic across platforms
Hands-on experience or equivalent training with Microsoft Defender for XDR, including deep familiarity with its sub-components: Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps (Note: Microsoft Defender XDR was released March 2026 — equivalent platform knowledge and migration readiness will be considered in place of tenure)
Demonstrated experience with or direct involvement in a Sentinel-to-Defender XDR migration, or the ability to map Sentinel functionality to Defender XDR equivalents based on deep platform knowledge of both
Solid understanding of XDR concepts, cross-domain correlation, and automated incident response
Deep familiarity with the MITRE ATT&CK framework and its application to detection engineering
Experience with Azure Logic Apps, Power Automate, or similar automation platforms
Background in threat hunting, incident response, and SOC operations
Preferred Qualifications
-
Microsoft Certified: Security Operations Analyst Associate (SC-200) — strongly preferred
-
Microsoft Certified: Cybersecurity Architect Expert (SC-100) — a plus
-
Both certifications held simultaneously — this will stand out
-
Hands-on experience with Copilot for Security and AI-assisted investigation features in Defender XDR
-
Prior involvement in large-scale SIEM or XDR platform migrations
-
Background in CTI integration and tooling
-
Experience supporting global SOC teams across multiple regions
-
Familiarity with SOAR platforms, CRIBL, or similar tools in the SOC ecosystem
-
Exposure to digital forensics or agentic AI workflows in a security operations context
More at 3B Staffing