FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Kusto Query LanguageLog AnalyticsSIEM platformsMicrosoft SentinelMicrosoft DefenderCloud Security Posture ManagementWindows systemsLinux systemsnetwork security toolsincident response processes
Soft Skills
analytical skillsinvestigative skills
Tools & Technologies
Microsoft Defender XDRDefender for CloudAzureEntra IDfirewallsIDSIPS
Industry Keywords
Security Operations Centersecurity alertsincident responsethreat analysisaudit-defensible investigation
Tech Stack
Tools & technologiesAzureCloudFirewallsLinux
About the role
Key responsibilities & impact- Monitor security alerts and incidents in Microsoft Sentinel, Defender XDR, and Defender for Cloud
- Triage incoming alerts to determine severity, impact, and required response actions
- Differentiate between false positives, benign activity, and actionable threats using established playbooks
- Perform continuous monitoring of cloud, identity, endpoint, and network telemetry
- Investigate suspicious activity across Azure, Entra ID, Microsoft Defender XDR, and integrated data sources
- Correlate logs, events, and indicators to establish timelines and determine root cause
- Escalate confirmed or high-risk incidents to senior analysts or incident response teams
- Execute or recommend containment actions in accordance with defined procedures
- Utilize Kusto Query Language (KQL) and Log Analytics to analyze security data
- Correlate events across identity, endpoint, network, and cloud workloads
- Identify trends, anomalies, and patterns indicative of malicious activity
- Create and maintain detailed, audit-defensible investigation notes and case records
- Document all triage decisions, escalation rationale, and response actions
- Produce incident summaries and reporting for internal stakeholders and clients
Requirements
What you’ll need- 1+ years of experience in a Security Operations Center or related security role
- Hands-on experience with SIEM platforms (Microsoft Sentinel preferred)
- Experience analyzing logs from one or more of the following:
- - Azure / Entra ID
- - Microsoft Defender (Endpoint, Identity, Cloud, Office 365)
- - Windows / Linux systems
- - Network security tools (firewalls, IDS/IPS)
- - Cloud Security Posture Management - Defender for Cloud
- Basic understanding of incident response processes and frameworks
- Strong analytical and investigative skills
Benefits
Comp & perks- This is a contractor position in the United States with the ability to work from home but may require travel to a client site.
- Atmosera is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
