
Senior Cybersecurity Engineer
teleion
Job description
- Must be living in the following states to be considered: Florida (FL), Georgia (GA) , Illinois (IL), Iowa (IA), Nevada (NV), North Carolina (NC), South Dakota (SD), Texas (TX), Washington (WA), Virginia (VA), Wisconsin (WI)
Senior Cybersecurity Engineer, Cloud & IR
Come join one of Pacific Northwest's Best Places to work! Our culture at Teleion embodies the spirit of a startup with a sense of ownership and an employee-led business model. Employees can grow their career and have fun while doing it!
About the Role
Teleion is seeking a Senior Cybersecurity Engineer to strengthen cloud security posture, mature incident response capabilities, and advance data security and zero trust for our enterprise clients. This is a hands-on, client-facing contract role spanning detection engineering, real incident ownership, Microsoft Purview and DLP, and Azure cloud hardening โ all within the Microsoft security ecosystem. The ideal candidate brings deep, production-configured expertise across the full Microsoft security stack and has led real incidents from containment through post-incident reporting.
Responsibilities
-
Configure, tune, and operate the full Microsoft security stack in production client environments: Microsoft Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
-
Lead incident response for real security events โ account compromise, data exfiltration, insider risk, BEC โ through the full lifecycle: containment, eradication, recovery, evidence preservation, and post-incident reporting.
-
Coordinate with MXDR or managed SOC providers on escalation quality, handoff, and case closure standards.
-
Author and maintain KQL analytic rules and hunting queries in Microsoft Sentinel, map detections to MITRE ATT&CK, close coverage gaps, and tune for signal quality and ingestion cost.
-
Develop SOAR playbooks to reduce false positive volume and automate analyst workflows.
-
Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps โ driving findings to closure, not just alerting.
-
Implement and maintain sensitivity labels, auto-labeling at scale, Insider Risk Management, and eDiscovery support.
-
Harden Azure and multi-cloud environments against benchmarks: remediate Defender for Cloud findings, drive secure score improvement, and address cloud identity and entitlement risk.
-
Advance zero trust maturity across identity, device, network, application, and data pillars using Conditional Access, PIM, device compliance, and least-privilege access patterns.
-
Build PowerShell and Microsoft Graph API automations to scale security operations, reporting, and remediation.
-
Design and run tabletop exercises to test and mature the client's incident response capability.
Requirements
-
7 or more years of security engineering or security operations experience in enterprise environments.
-
Deep, production-configured hands-on experience across the full Microsoft security stack: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune, and Microsoft Purview.
-
Demonstrated leadership of real security incidents โ not tabletop only โ through the full lifecycle including containment, eradication, recovery, and post-incident reporting.
-
Strong KQL proficiency: authoring analytic rules, developing hunting queries, tuning for cost and signal quality, and mapping to MITRE ATT&CK.
-
Direct, demonstrable Microsoft Purview experience: DLP policy design and tuning, sensitivity labels, Insider Risk Management, and eDiscovery.
-
Experience hardening Azure environments: remediating Defender for Cloud findings, driving secure score improvement, and addressing cloud identity and entitlement risk.
-
Experience implementing zero trust controls across multiple pillars using Conditional Access, PIM, and privileged access management.
-
Proficiency in PowerShell and Microsoft Graph API for security automation.
-
Experience coordinating with MXDR or managed SOC providers on escalation and case quality.
-
Certifications preferred: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, or CISSP. Digital forensics experience in cloud and M365 environments is a plus.
Teleion offers full benefits, PTO, holiday, 401(k). See how other employees have reviewed us on Glassdoor. We are excited to announce we have made in on Seattle Business Magazines "Washingtons Best Place to Work" for the 6th year in a row. (https://seattlebusinessmag.com/100-best-companies-work/100-best-companies-work-midsize)
Teleion is minority owned and an Equal Opportunity Employer โ We welcome all races, sexual orientations, gender identities, veterans, religions and disabilities.
Salary range: $155,000 - $200,000 - Based on experience