Senior Detection & Response Engineer
Core
Map Microsoft security telemetry, tune detections, and automate investigative workflows for SOC analysts.
Role type
Senior Detection & Response Engineer (Microsoft Security Stack)
Builds
Production detections and automation for Defender XDR, Entra ID, Sentinel, and Microsoft Graph
Domain
Cybersecurity, Cloud Security, Identity Security
Required skills
Microsoft Defender XDR, Entra ID, Microsoft Sentinel, Microsoft Graph, KQL, Python, Sigma, Windows internals, API integration
Preferred skills
SC-200, AZ-500, SC-300, AWS, GCP, non-Microsoft EDR/SIEM
Technologies
Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, Microsoft 365, KQL, Python, Sigma, Claude Code
Responsibilities
Build and maintain a living map of Microsoft security signal; Track signal changes and turn material changes into concrete actions; Write and tune custom detections against Microsoft data sets; Automate Microsoft-specific investigative workflows against Graph, Defender, Sentinel, and Entra APIs; Partner with Engineering on Microsoft integrations; Mentor SOC analysts and answer hard questions from SOC, CS, and Sales
Seniority
Senior, hands-on IC