Security Operations Lead designing Microsoft Sentinel and managing security operations at PwC. Collaborating with teams to enhance client security through advanced technology.
Responsibilities
Design and implement Microsoft Sentinel as the primary SIEM platform
Develop advanced detection content including analytics rules, hunting queries, workbooks, and threat models
Integrate and manage XDR across endpoints, identity, cloud apps, and email
Lead MCP integration by connecting Microsoft Copilot for Security with Sentinel, SOAR, and cloud services
Operationalize AI workflows for triage, enrichment, and investigation
Build and maintain playbooks using Logic Apps, Azure Automation, PowerShell, and Python
Develop SOAR workflows that reduce manual steps and accelerate incident response times
Establish and lead a program for automated patch management
Requirements
5+ years of experience in security operations, SIEM engineering, or security monitoring with Microsoft technologies
Proven experience implementing and tuning Microsoft Sentinel detections, investigations, dashboards, and automation playbooks in enterprise environments
Experience integrating Defender XDR, identity, endpoint, email, and cloud telemetry to support unified detection and response workflows
Strong knowledge of Microsoft Sentinel architecture, analytics rules, workbooks, KQL, data connectors, and log normalization practices
Good understanding of Defender XDR, Microsoft 365 security, Entra ID, Azure security services, and hybrid cloud security operations
Familiarity with incident response lifecycle, threat detection engineering, vulnerability management, and control frameworks like CIS and NIST.
SOC Analyst monitoring detections for clients, executing response playbooks, and improving threat detection capabilities. Join Arctiq to protect organizations in today's digital landscape.
Lead SOC Analyst at IFS responsible for protecting global SaaS platform and internal systems. Collaborating across security teams to enhance security operations, detection, and response capabilities.
Senior Security Operations Engineer driving security incident response efforts for Affirm's systems and customers. Collaborating with teams to improve security posture and build automated playbooks.
Cybersecurity Analyst providing first - level incident response and client support at CDW. Monitoring security incidents, providing client communications, and engaging in professional development activities.
Business Development Manager responsible for sales engagements with Field Sales teams. Driving SecOps product revenue objectives and solving complex security challenges.
Security Operations Analyst part of Diligent’s Security team ensuring safety and compliance for personnel and assets. Monitoring security alerts and managing incident responses effectively.
Trust & Safety Senior Associate in InfoSec Ops at Instacart ensuring data safety through collaboration and operational management responsibilities. Focus on vendor data practices, audit readiness, and project leadership.
Security Operations Specialist providing second - level technical client support for cyber incidents and system issues at CDW. Requires a degree and security experience in a client - focused environment.