Teleion Consulting is seeking a hands-on, client-facing Senior Cybersecurity Engineer to improve cloud security posture, strengthen incident response, and mature data security and zero trust across the Microsoft security ecosystem.
Responsibilities
- Configure, tune, and operate the Microsoft security stack in production client environments, including Microsoft Sentinel , Defender XDR , Defender for Cloud , Entra ID , Intune , and Microsoft Purview .
- Lead incident response for real security events, including account compromise , data exfiltration , insider risk , and BEC , covering containment, eradication, recovery, evidence preservation, and post-incident reporting.
- Coordinate with MXDR or managed SOC providers to maintain escalation quality, handoff standards, and case closure practices.
- Author and maintain KQL analytic rules and hunting queries in Microsoft Sentinel; map detections to MITRE ATT&CK , close coverage gaps, and tune for signal quality and ingestion cost.
- Develop SOAR playbooks to reduce false positives and automate analyst workflows.
- Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps, driving findings to closure.
- Implement and maintain sensitivity labels , auto-labeling at scale, Insider Risk Management , and eDiscovery support.
- Harden Azure and multi-cloud environments by remediating Defender for Cloud findings, improving secure score , and addressing cloud identity and entitlement risk.
- Advance zero trust maturity across identity, device, network, application, and data pillars using Conditional Access , PIM , device compliance, and least-privilege access patterns.
- Build PowerShell and Microsoft Graph API automations to scale security operations, reporting, and remediation.
- Design and run tabletop exercises to test and mature the client incident response capability.
Requirements
- 7+ years of security engineering or security operations experience in enterprise environments.
- Deep, production-configured hands-on experience across the full Microsoft security stack: Sentinel , Defender XDR , Defender for Cloud , Entra ID , Intune , and Microsoft Purview .
- Demonstrated leadership handling real security incidents through the full lifecycle, including containment, eradication, recovery, and post-incident reporting.
- Strong KQL proficiency: analytic rule creation, hunting query development, tuning for cost and signal quality, and mapping to MITRE ATT&CK .
- Direct, demonstrable Microsoft Purview experience covering DLP policy design and tuning, sensitivity labels , Insider Risk Management , and eDiscovery .
- Experience hardening Azure environments by remediating Defender for Cloud findings, improving secure score , and addressing cloud identity and entitlement risk.
- Experience implementing zero trust controls across multiple pillars using Conditional Access and PIM and privileged access management.
- PowerShell and Microsoft Graph API proficiency for security automation.
- Experience coordinating with MXDR or managed SOC providers on escalation and case quality.
- Certifications preferred: AZ-500 , SC-200 , SC-400 , SC-100 , GCIH , GCFA , or CISSP . Digital forensics experience in cloud and M365 environments is a plus.
Technologies
- Microsoft Sentinel
- Defender XDR
- Defender for Cloud
- Entra ID
- Intune
- Microsoft Purview
- KQL
- MITRE ATT&CK
- SOAR
- Microsoft Graph API
- PowerShell
- Conditional Access
- PIM
- Insider Risk Management
- eDiscovery
- DLP
- SharePoint
- OneDrive
- Teams
- Azure
- Microsoft security ecosystem
- MXDR
- Managed SOC providers
- Sensitivity labels
- Device compliance
- Least-privilege access patterns
- Tabletop exercises
Job Details
- Location: Seattle, WA (onsite)
- Compensation: USD 155,000 - 200,000 per year
- Employment type: contract
Benefits
- Full benefits
- PTO
- Holiday
- 401(k)
Senior Cybersecurity Engineer in seattle at Unknown Company
This position is listed as contract and onsite.