Overview
As a Security Content Engineer, you will develop and optimize high-fidelity detection content in the Microsoft Sentinel environment and automate security workflows. You will manage a portfolio of detection content, tune detections to reduce false positives, and lead threat-informed research to build proactive detection strategies. You’ll collaborate with engineering teams to improve log ingestion and automation frameworks, delivering measurable improvements for global clients. This remote role offers impactful work at scale within a fast-paced, security-focused team.
Pay / Benefits
- competitive compensation
- comprehensive benefits
- flexible work arrangements
- opportunities for professional growth and development
Responsibilities
- Develop, test, and maintain detection content in KQL for Microsoft Sentinel
- Tune and optimize detections to reduce alert fatigue and improve SOC outcomes
- Lead threat-informed research on emerging threats and attack vectors
- Design and implement scalable automation for security workflows (onboarding, incident enrichment)
- Serve as a technical resource for clients on complex tuning requests
- Collaborate with integration teams to optimize log ingestion
- Improve security policies and automation frameworks based on hands-on experience
Key requirements
- 5-8 years in Detection Engineering, SOC, or similar content-creation role
- Deep hands-on expertise with Microsoft security stack (Microsoft Sentinel, Defender, Logic Apps)
- High proficiency in KQL with complex, optimized queries
- Experience automating security workflows using SOAR, APIs, or scripting (Python, PowerShell)
- Ability to work autonomously with competing priorities
- Knowledge of attacker TTPs and MITRE ATT&CK framework
- Strong analytical and problem-solving skills with deep log analysis and forensics
- Excellent collaboration and communication skills
- collaboration
- communication
- problem-solving
- Kusto Query Language (KQL)
- Microsoft Sentinel
- Microsoft 365 Defender
…
