Microsoft Security Automation & Incident Response Engineer - Contract Position
Magnet Forensics Microsoft Security Automation & Incident Response Engineer - Contract Position
Magnet Forensics is seeking a highly skilled Microsoft Security Automation & Incident Response Engineer to accelerate the maturity and efficiency of our security operations program.
This resource will be responsible for optimizing and integrating Microsoft's security platform, reducing manual analyst workload, automating repetitive tasks, improving detection coverage, and enhancing incident response capabilities.
The ideal candidate is a hands-on engineer with deep experience in Microsoft Sentinel, Defender XDR, automation, and modern security operations.
This is a 3-4 month contract role
What You'll Do
Security Operations Optimization
- Analyze existing alert triage and incident response processes
- Identify operational bottlenecks and manual activities
- Implement improvements that reduce analyst effort and response times
- Improve overall SOC efficiency and effectiveness
- Tune Microsoft Sentinel analytics rules
- Reduce false positives and alert fatigue
- Create advanced correlation rules and hunting content
- Improve quality and fidelity of security detections
- Alert enrichment
- Incident routing
- Ticket creation
- Escalation workflows
- Investigation support
- Standard response actions
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Entra ID
- Zscaler telemetry
- Existing ITSM and ticketing platforms
- Improve incident response processes
- Enhance investigation playbooks
- Develop response automation
- Create operational runbooks and documentation
Detection Engineering
Security Automation
Design and implement automation for:
Platform Integration
Optimize and integrate:
Incident Response Support
What We're Looking For
Required Qualifications
- 5+ years in Security Operations, Detection Engineering, or Incident Response
- Strong Microsoft Sentinel experience
- Strong Microsoft Defender suite experience
- Advanced KQL skills
- Logic Apps experience
- SOAR automation experience
- SIEM engineering experience
- Security operations workflow optimization experience
- Microsoft Security certifications
- Threat hunting experience
- Detection engineering background
- Experience integrating third-party security telemetry
- Exposure to Purview and DLP technologies
Preferred Qualifications
Skills
As published by lever · 10 questions · 1 written answer
Basics
Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website
Short answers (2)
- Please enter the country you are legally registered to work in.
- What are your total annual salary expectations (OTE)?
Pick from a list (7)
- How did you hear about us? optional
- Have you previously been employed by Magnet Forensics (or acquired/merged company) in any capacity? (i.e. employee, contractor, co-op, vendor)? optional
- Will you require sponsorship or other assistance or support to be authorized to, or otherwise, work from your country of residence? optional
- Work authorization optional
- What is your notice period to begin working with Magnet Forensics? optional
- I have read and agree to the Applicant Privacy Notice and understand how my personal information will be used (http://bit.ly/3Lj7cbk) also accessible under Job Postings on our Careers page optional
- This is a 3-4 month long contract position, are you comfortable with that length of contract? optional
Written answers (1)
- If you were referred to Magnet, who referred you? (Note: We may verify referral details internally.) optional