Job Description
We are looking for a Security Consultant to join our team and take a proactive role in enhancing cybersecurity defenses using Microsoft Defender and Microsoft Sentinel.
- This role involves deploying, configuring, and optimizing security solutions to ensure advanced threat detection, response, and real-time monitoring.
- If you are passionate about cybersecurity, automation, and threat intelligence, we want to hear from you!
Key Responsibilities
- Integrate Microsoft Defender for Endpoint, Defender for Identity, and Defender for Servers into the security infrastructure.
- Deploy and configure Microsoft Defender for Endpoint (MDE) on on-premise Windows and Linux servers for advanced protection.
- Create and automate security response playbooks using Logic Apps & Defender XDR.
- Utilize Advanced Hunting (Kusto Query Language – KQL) to analyze threat activity and improve detection capabilities.
- Deploy and configure Microsoft Sentinel to monitor and protect on-premises infrastructure.
- Set up and manage Log Analytics workspaces for seamless data ingestion from multiple security sources.
- Configure Syslog, CEF, and Windows Event Forwarding for security devices, firewalls, and SIEM logs.
- Develop custom KQL queries to analyze security logs and detect anomalies.
- Design real-time monitoring dashboards and workbooks for security insights.
- Implement alert rules and incident response playbooks to automate threat detection and response.
Required Skills & Qualifications
- Proven experience in Microsoft Security technologies, including Defender for Endpoint, Defender for Identity, and Defender for Servers.
- Microsoft Sentinel deployment and SIEM configurations.
- threat detection, incident response, and automation.
- Kusto Query Language (KQL) for threat analysis.
- Log Analytics, security event forwarding, and integration of various log sources.
- Ability to create custom playbooks and automate security workflows using Logic Apps.
- Strong problem-solving skills
- Industry certifications like Microsoft Security Operations Analyst (SC-200) or Microsoft Cybersecurity Architect (SC-100) are a plus.
Hiring Team Member
