Description
Core Focus Areas
Security Operations, Monitoring & Threat Defense
- Monitor security logs and alerts across SIEM and Microsoft Defender (XDR); investigate, triage, and respond to potential incidents.
- Operate and help tune endpoint/EDR coverage (Microsoft Defender, CrowdStrike) and assist with firewall, IDS/IPS, and edge controls (Fortinet) under senior direction.
- Run vulnerability scanning, patch/remediation tracking, and alert tuning to reduce false positives while preserving detection coverage.
Identity & Microsoft 365 Security
- Help administer Microsoft Entra identity and access - conditional access, MFA, identity protection, and least-privilege roles - applying Zero Trust principles.
- Maintain Microsoft 365 security and compliance configuration across Exchange Online, SharePoint/OneDrive, and Teams, keeping settings hardened and consistent.
Data Protection & AI Governance
- Build, deploy, and tune DLP, sensitivity labeling, encryption,