Also available on
Job Description
📋 Description Lead investigations end-to-end and manage MSSP escalations. Conduct proactive threat hunts across cloud and endpoints. Build and tune detection content in Microsoft Sentinel and cloud stack. Develop and improve enrichment and response workflows to speed up response. Apply AI-assisted approaches to triage and automation. Analyze logs and telemetry to reconstruct attacker activity. 🎯 Requirements Proven IR and security operations in cloud-native environments (Azure & AWS). Hands-on expertise with Microsoft Sentinel or equivalent SIEM for detection engineering. Experience working with MSSP—managing escalations, feedback, and coverage gaps. Threat hunts and automation, including SOAR playbooks and scripting. Strong knowledge of attacker TTPs, MITRE ATT&CK, cloud security, and identity (AD/Entra ID). Excellent communication and ability to work independently and in a team. 🎁 Benefits Remote-first culture. Flexible PTO and self-care days. Parental leave. Comprehensive health coverage (including dependents). Home office setup stipend. Learning stipend for professional development.