Remote job
Senior Detection & Response Engineer
Job details
About this role
Role overview
This position centers on owning detection coverage across the Microsoft security ecosystem for a managed detection and response organization. The engineer serves as the internal authority on Microsoft telemetry, translating how Defender XDR, Entra ID, Sentinel, Graph, Azure, and Microsoft 365 actually behave in production into reliable, tuned detections that protect a diverse customer base.
Responsibilities
- Maintain a living map of Microsoft security signal, including ingestion lag, retention windows, gating license tiers, and known gaps between documentation and reality - Track changes across the Microsoft product surface and turn each material shift into concrete detection updates before coverage drifts - Build and tune detections in the organization's rule engine, deciding where native alerts are sufficient and where a custom layer is required - Automate investigative workflows against the Graph, Defender, Sentinel, and Entra APIs to accelerate analyst triage - Partner with engineering on ingestion pipelines, schema mapping, API throttling, and integration reliability - Mentor SOC analysts and answer hard technical questions from customer-facing and revenue teams, including candid conversations about coverage limits
Requirements
- 5+ years in IT or security operations, with substantial hands-on time defending Microsoft environments - Deep current knowledge of Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID, Sentinel, Graph, Azure, and Microsoft 365 - Strong KQL fluency for both Defender Advanced Hunting and Sentinel, including schema differences, optimization, and debugging - Working knowledge of Graph, Graph Security, Defender, and Sentinel APIs, including authentication, permissions, versioning, and throttling - Solid grasp of Entra ID and legacy Active Directory attack surface, including authentication flows, conditional access, OAuth consent, token theft and replay, hybrid identity, and privileged role abuse - Proficiency with Python and Sigma, plus demonstrated use of AI coding tools such as Claude Code for systems and data work - Comfort on the command line across Windows, macOS, and Linux
Nice to have
- Certifications such as SC-200, AZ-500, or SC-300; demonstrated depth matters more than any single credential - Exposure to non-Microsoft stacks including AWS, GCP, and other EDR or SIEM platforms
Benefits and work setup
- Remote work option available for candidates based in the United States; visa sponsorship is not offered - Base salary range of $142,900 to $207,200 USD, with bonus eligibility and equity, targeting $160,000 to $192,000 for most hires - Unlimited paid time off, location flexibility, up to 24 weeks of parental leave, and comprehensive health benefits