EngineerJobs.io
← Back to all jobs

Job Description

Teleion Consulting is hiring a hands-on, client-facing Senior Cybersecurity Engineer to help strengthen cloud security posture and operational readiness for real-world threats. This onsite contract role in Seattle, WA focuses on maturing incident response, advancing data protection, and improving zero trust capabilities across the Microsoft security ecosystem, including Sentinel, Defender, Entra, Intune, and Microsoft Purview.

You will directly support production client environments by configuring and operating Microsoft security tools, leading incident response activities end-to-end, and building durable detection and automation workflows that reduce noise and improve analyst efficiency. The role also includes improving security hygiene in Azure and multi-cloud settings through benchmark remediation and identity and entitlement risk reduction.

Responsibilities

  • Configure, tune, and operate the Microsoft security stack in production client environments, including Microsoft Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
  • Lead incident response for real security events such as account compromise, data exfiltration, insider risk, and BEC, covering containment, eradication, recovery, evidence preservation, and post-incident reporting.
  • Coordinate with MXDR or managed SOC providers on escalation quality, handoff, and case closure standards.
  • Author and maintain KQL analytic rules and hunting queries in Microsoft Sentinel, map detections to MITRE ATT&CK, close coverage gaps, and tune for signal quality and ingestion cost.
  • Develop SOAR playbooks to reduce false positive volume and automate analyst workflows.
  • Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps, moving findings to closure rather than alerting only.
  • Implement and maintain sensitivity labels, auto-labeling at scale, Insider Risk Management, and eDiscovery support.
  • Harden Azure and multi-cloud environments by remediating Defender for Cloud findings, driving secure score improvement, and addressing cloud identity and entitlement risk.
  • Advance zero trust maturity across identity, device, network, application, and data pillars using Conditional Access, PIM, device compliance, and least-privilege access patterns.
  • Build PowerShell and Microsoft Graph API automations to scale security operations, reporting, and remediation.
  • Design and run tabletop exercises to test and mature the client’s incident response capability.

Requirements

  • 7+ years of security engineering or security operations experience in enterprise environments.
  • Production-configured hands-on experience across the full Microsoft security stack: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
  • Demonstrated leadership of real security incidents through the full lifecycle, including containment, eradication, recovery, and post-incident reporting.
  • Strong KQL proficiency, including analytic rules, hunting queries, tuning for cost and signal quality, and mapping to MITRE ATT&CK.
  • Direct, demonstrable Microsoft Purview experience across DLP policy design and tuning, sensitivity labels, Insider Risk Management, and eDiscovery.
  • Experience hardening Azure environments: remediating Defender for Cloud findings, driving secure score improvement, and addressing cloud identity and entitlement risk.
  • Experience implementing zero trust controls across multiple pillars using Conditional Access and PIM (privileged access management).
  • PowerShell and Microsoft Graph API proficiency for security automation.
  • Experience coordinating with MXDR or managed SOC providers on escalation and case quality.
  • Certifications preferred: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, or CISSP. Cloud and M365 digital forensics experience is a plus.

Benefits

  • Full benefits
  • PTO
  • Holiday
  • 401(k)

Salary: USD 155,000 - 200,000 per year. Location: Seattle, WA (onsite). Job type: contract.

Similar Jobs