Job Description
Security Consultant – SecOps is a job opening in Microsoft for assisting customers with their modern SecOps in hybrid and multi-cloud deployments. In this job, the candidate is required to design and implement Microsoft Sentinel, Defender XDR, Security Copilot, and agentic SOC features with the purpose of improving detection, investigation, response, and resilience. The candidate duties will include conducting SecOps discovery workshops, evaluating the maturity of SOC, creating modernization plans, configuring Sentinel architecture, creating KQL hunting logic, and creating IR workflows.
Experience: 5+ years of experience in cybersecurity consulting, security operations, SOC engineering, incident response, SIEM/SOAR, or related security delivery roles.
Apply: Click Here
Responsibilities
- Run SecOps discovery sessions, evaluate SOC maturity, spot gaps, and draw up security modernization roadmaps.
- Design and implement architectures of Microsoft Sentinel, including data ingestion, analytics rules, automation playbooks, workbooks, incident enrichment, and reporting.
- Implement Defender XDR based on endpoint, identity, cloud, email, and SaaS security signals to improve detection and response.
- Design threat hunting with KQL hunting logic, incident triage workflows, response playbooks, and other reusable delivery artifacts.
- Leverage Security Copilot and agentic SOC models with built-in human-in-the-loop validation and safety controls.
Qualifications
- Minimum 5+ years of experience in cybersecurity consulting, security operations, SOC engineering, incident response, SIEM/SOAR, or any other security delivery function.
- Practical experience using Microsoft Sentinel & Defender for two workloads.
- Expert in detection engineering, triaging, threat hunting, investigations, containment, mitigation, and SOC governance.
- Knowledgeable on customer deliverable architecture, discovery, deployment design, design considerations, risk register, and runbook.
- Knowledge of KQL, Microsoft security logs, identity and endpoint data signals, cloud security data telemetry, and attack patterns.
Preferred Qualifications
- Exposure to building reusable accelerators, templates, workshops, and enablement documents through lessons learned in projects.
- Skilled at working in multi-cloud as well as hybrid customer environments.
- Knowledge of ITSM, CMDB, ticketing, Threat Intel, and Vulnerability Management Integration solutions.
- Experience in automation solutions like Logic Apps, Azure Functions, PowerShell, APIs, Managed Identities.
- Experience in communicating security principles to technical staff and program managers.