Cybersecurity Engineer
Azure Conditional Access
Azure Security
Azure Security Posture Management
Cloud Platforms
Cloud Security
Cybersecurity Analysis
Cybersecurity Tools
Data Security
Defender For Cloud
Endpoint Security
Identity and Access Management
Information Security
InfoSec
Microsoft Azure Security
Microsoft Defender For Endpoint
Microsoft Defender Xdr
Microsoft Purview
Job Description
Lead client-ready Microsoft security delivery as a Senior Cybersecurity Engineering Consultant focused on Microsoft Purview, Defender XDR, Entra ID hardening, and Azure security posture assessments for onsite work across the United States.
Responsibilities
- Lead Purview engagements including current-state assessment, target design, phased rollout, and configuration of scoped capabilities such as information protection, DLP, audit, and related controls.
- Implement and harden Microsoft Defender XDR and Entra ID security, covering Conditional Access and identity-protection patterns aligned to the client’s operating model (not a demo tenant).
- Deliver Azure security posture assessments and guided hardening across landing-zone and control-plane hygiene, Defender for Cloud, and a prioritized hardening roadmap.
- Where scoped, perform assessment-level Active Directory and hybrid identity work including privilege, delegation, legacy protocol exposure, and a prioritized hardening roadmap.
- Create client-ready artifacts including gap analyses, configuration baselines, implementation plans, and operational handover that can be executed.
- Run workshops with security, compliance, identity, and IT stakeholders to capture requirements, decisions, risks, and scope changes.
- Support pre-sales with effort estimates, technical scope definition, and solution shaping.
Requirements
- Senior consulting or professional-services delivery experience, including running workshops and delivering scope and artifacts the client accepted.
- Hands-on Microsoft Purview implementation in a production or client tenant, including designing and configuring controls.
- Hands-on Microsoft Defender XDR experience, with Defender for Endpoint plus at least one of Identity, Office, or Cloud Apps.
- Hands-on Entra ID security experience, including Conditional Access, identity protection / risk patterns, and privileged-access basics as implemented in the tenant.
- Ability to assess requirements and recommend a target configuration with practical implementation guidance, including what to phase and what not to enable.
Technologies
- Microsoft Purview
- Microsoft Defender XDR (including Defender for Endpoint)
- Entra ID
- Conditional Access
- identity protection / risk patterns
- Microsoft Defender for Cloud
- Azure security posture assessments
- Active Directory
- Microsoft Sentinel
- AWS
Strongly Preferred
- Active Directory security assessments in hybrid estates: privilege, stale admin paths, legacy auth, and a hardening roadmap.
- Azure security assessments and control implementation, including Defender for Cloud.
- Landing Purview, Defender, and Entra telemetry in Microsoft Sentinel (connectors, data usefulness, detections).
Useful
- AWS or multi-cloud posture reviews.
- Network-edge reviews on occasional engagements, including firewall/VPN policy, logging, and segmentation.
Certifications (Desirable)
- Most relevant: SC-400; SC-300; SC-200
- Also useful: SC-500 (AZ-500); SC-100; CISSP or CISM
Location: United States (onsite)
Salary: USD 85,000 - 120,000 per yearly