EngineerJobs.io
← Back to all jobs

Job Description

Lead client-ready Microsoft security delivery as a Senior Cybersecurity Engineering Consultant focused on Microsoft Purview, Defender XDR, Entra ID hardening, and Azure security posture assessments for onsite work across the United States.

Responsibilities

  • Lead Purview engagements including current-state assessment, target design, phased rollout, and configuration of scoped capabilities such as information protection, DLP, audit, and related controls.
  • Implement and harden Microsoft Defender XDR and Entra ID security, covering Conditional Access and identity-protection patterns aligned to the client’s operating model (not a demo tenant).
  • Deliver Azure security posture assessments and guided hardening across landing-zone and control-plane hygiene, Defender for Cloud, and a prioritized hardening roadmap.
  • Where scoped, perform assessment-level Active Directory and hybrid identity work including privilege, delegation, legacy protocol exposure, and a prioritized hardening roadmap.
  • Create client-ready artifacts including gap analyses, configuration baselines, implementation plans, and operational handover that can be executed.
  • Run workshops with security, compliance, identity, and IT stakeholders to capture requirements, decisions, risks, and scope changes.
  • Support pre-sales with effort estimates, technical scope definition, and solution shaping.

Requirements

  • Senior consulting or professional-services delivery experience, including running workshops and delivering scope and artifacts the client accepted.
  • Hands-on Microsoft Purview implementation in a production or client tenant, including designing and configuring controls.
  • Hands-on Microsoft Defender XDR experience, with Defender for Endpoint plus at least one of Identity, Office, or Cloud Apps.
  • Hands-on Entra ID security experience, including Conditional Access, identity protection / risk patterns, and privileged-access basics as implemented in the tenant.
  • Ability to assess requirements and recommend a target configuration with practical implementation guidance, including what to phase and what not to enable.

Technologies

  • Microsoft Purview
  • Microsoft Defender XDR (including Defender for Endpoint)
  • Entra ID
  • Conditional Access
  • identity protection / risk patterns
  • Microsoft Defender for Cloud
  • Azure security posture assessments
  • Active Directory
  • Microsoft Sentinel
  • AWS

Strongly Preferred

  • Active Directory security assessments in hybrid estates: privilege, stale admin paths, legacy auth, and a hardening roadmap.
  • Azure security assessments and control implementation, including Defender for Cloud.
  • Landing Purview, Defender, and Entra telemetry in Microsoft Sentinel (connectors, data usefulness, detections).

Useful

  • AWS or multi-cloud posture reviews.
  • Network-edge reviews on occasional engagements, including firewall/VPN policy, logging, and segmentation.

Certifications (Desirable)

  • Most relevant: SC-400; SC-300; SC-200
  • Also useful: SC-500 (AZ-500); SC-100; CISSP or CISM

Location: United States (onsite)

Salary: USD 85,000 - 120,000 per yearly

Similar Jobs