About this role
Operate and improve threat detection and security monitoring across Microsoft 365, cloud, and SaaS environments. Design security controls, optimize Microsoft Sentinel SIEM, and lead escalations and investigations with strong stakeholder communication.
Key Responsibilities
- Design, implement, and improve security controls across cloud and SaaS environments
- Architect and optimize Microsoft Sentinel SIEM using connectors, ingestion, analytics rules, and KQL
- Administer and optimize CrowdStrike Falcon for endpoint protection, EDR, and threat hunting
- Implement and manage Zscaler (ZIA/ZPA) for Zero Trust access and secure connectivity
- Serve as senior escalation point for incidents, investigations, and root-cause analysis
Technical Overview
Hands-on security engineering for Microsoft Entra ID (Azure AD), Microsoft Defender suite, and Microsoft Sentinel SIEM using KQL, analytics rules, data connectors, workbooks, and automation. Also administer CrowdStrike Falcon for endpoint detection and EDR and implement Zscaler (ZIA/ZPA) for Zero Trust access and secure connectivity.
Ideal Candidate
The ideal candidate is a senior cybersecurity engineer with 7+ years of enterprise security experience and deep hands-on knowledge of the Microsoft security stack. They will be highly skilled in Microsoft Sentinel SIEM (KQL, analytics rules, workbooks, automation), threat hunting, and operating CrowdStrike Falcon and Zscaler (ZIA/ZPA) within cloud-first, Zero Trust environments.
Must-Have Skills
Bachelor’s Degree7+ years of enterprise cybersecurity experienceMicrosoft security ecosystem expertiseDesignimplementand continuously improve security controls across cloud and SaaS environmentsArchitectdeployand operate security solutions across the Microsoft 365 ecosystemBuildtuneand optimize Microsoft Sentinel SIEMAdminister and optimize CrowdStrike Falcon for endpoint protectionEDRand threat huntingImplement and manage Zscaler (ZIA/ZPA) for Zero Trust access
Nice-to-Have Skills
Not specified
Tools & Platforms
Microsoft Entra IDAzure ADConditional AccessIdentity ProtectionMicrosoft Defender for EndpointMicrosoft Defender for IdentityMicrosoft Defender for Cloud AppsMicrosoft Defender for Office 365Microsoft SentinelKQLMicrosoft Sentinel SIEMCrowdStrike FalconZscaler (ZIA)Zscaler (ZPA)EDRZero Trust
Required Skills
Microsoft SentinelSIEMKQLMicrosoft Entra IDAzure ADConditional AccessIdentity ProtectionMicrosoft Defender for EndpointMicrosoft Defender for IdentityMicrosoft Defender for Cloud AppsMicrosoft Defender for Office 365CrowdStrike FalconEDRZscaler ZIAZscaler ZPAZero Trustincident responseSOCthreat huntingroot-cause analysis
Hard Skills
Designimplementand continuously improve security controls across cloud and SaaS environmentsSecurity incident escalation pointIncident investigationsRoot-cause analysisDetection engineeringThreat huntingMicrosoft Entra ID (Azure AD)Conditional AccessIdentity ProtectionMicrosoft Defender for EndpointMicrosoft Defender for IdentityMicrosoft Defender for Cloud AppsMicrosoft Defender for Office 365Microsoft Sentinel SIEMData connectorsIngestionAnalytics rulesKQL queriesWorkbooksAutomationMicrosoft 365 ecosystem securityCrowdStrike FalconEDR (Endpoint Detection and Response)Threat hunting with CrowdStrikeZscaler (ZIA/ZPA)Zero Trust accessEnterprise networking conceptsCloud networkingSecure access architecturesTraffic inspectionSegmentationGovernanceRisk & best practices across cybersecurity domainsIdentity & Access ManagementCloud & SaaS SecurityEndpoint SecurityNetwork SecurityData ProtectionSecurity Monitoring & Incident ResponseVulnerability & Risk ManagementAuditsRisk assessmentsCompliance initiativesSecurity policiesstandardsproceduresand technical documentation
Soft Skills
Clear professional communication to technical and non-technical stakeholdersCustomer-service mindsetConfident stakeholder engagementLeadership in escalationsCross-team partnership (SOC and incident response providers)Continuous improvement mindsetExceptional interpersonal skillsAbility to deliver security solutions with customer-first mindset
Keywords for Your Resume
THREAT DETECTION ENGINEERSenior Cybersecurity Engineerenterprise cybersecurity experienceMicrosoft security ecosystemMicrosoft 365Microsoft Entra IDAzure ADConditional AccessIdentity ProtectionMicrosoft Defender for EndpointMicrosoft Defender for IdentityMicrosoft Defender for Cloud AppsMicrosoft Defender for Office 365Microsoft SentinelSIEMKQL queriesanalytics rulesworkbooksautomationthreat huntingdetection engineeringCrowdStrike FalconEDRZscaler (ZIA)Zscaler (ZPA)Zero Trustincident responseroot-cause analysisSOC
Deal Breakers
7+ years of enterprise cybersecurity experience, Deep hands-on knowledge of the Microsoft security ecosystem (Microsoft 365, Entra ID/Azure AD, Defender, Sentinel), Experience administering and optimizing CrowdStrike Falcon (endpoint protection, EDR, threat hunting), Experience implementing and managing Zscaler (ZIA/ZPA) and Zero Trust access
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile