Location: Remote Contract Type: Contract Duration: 2 months Rate: £440 - £490 per day INSIDE IR35
Overview
We are seeking an experienced Sentinel Defender to support the monitoring, investigation and response to cyber security incidents within a Microsoft security environment.
The successful candidate will play a key role in protecting business-critical systems through proactive threat detection, security monitoring and incident response activities.
Working as part of a wider Security Operations or Cyber Defence team, you will leverage Microsoft Sentinel and the Microsoft Defender suite to identify, investigate and remediate security threats across complex enterprise environments.
Key Responsibilities
Monitor and investigate security alerts generated by Microsoft Sentinel and Microsoft Defender. Perform triage and analysis of security incidents to determine impact and appropriate response actions. Conduct threat hunting activities to identify suspicious or malicious activity. Analyse logs and security telemetry from multiple data sources. Create, tune and optimise Sentinel analytics rules, workbooks and detection use cases. Support incident response activities, including containment, eradication and recovery. Maintain and improve security monitoring and alerting capabilities. Work closely with infrastructure, cloud, networking and application teams during investigations. Produce clear incident reports and security documentation. Contribute to continuous improvement of SOC processes, playbooks and detection engineering activities.
Required Skills & Experience
Strong hands-on experience with Microsoft Sentinel. Experience working with Microsoft Defender technologies, including: Microsoft Defender for Endpoint Microsoft Defender for Identity Microsoft Defender for Cloud Microsoft Defender for Office 365 Experience investigating and responding to cyber security incidents. Strong understanding of security operations and incident response processes. Experience analysing Windows security events, Azure logs and cloud telemetry. Knowledge of cyber security frameworks, attack methodologies and threat actor tactics. Experience developing and tuning SIEM detections. Strong Kusto Query Language (KQL) skills. Ability to work independently within a Security Operations environment. Excellent analytical and problem-solving skills.
Desirable Skills
Security Operations Centre (SOC) experience. Experience with Microsoft Defender XDR. Knowledge of MITRE ATT&CK framework. Experience with Azure security services. Experience building Sentinel workbooks and dashboards. Logic Apps and SOAR automation experience. Threat Intelligence integration experience. Microsoft security certifications Only candidates based in UK and eligible to work in UK are allowed
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UK.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast!
Find the best jobs in the UK, apply in 1 click and get a job today!