Microsoft Security Engineer

King & Spalding LLP

Atlanta (GA)

On-site

USD 110,000 - 140,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health and wellness plan
401(k) plan
Paid Time Off

Job summary

King & Spalding LLP is seeking a Microsoft Security Engineer to administer and optimize Microsoft security platforms, including Defender XDR and Sentinel, across the firm’s environments in a fast-paced enterprise. You’ll design policies, manage identities, and support security operations to strengthen the organization’s security posture.

The role requires 3–5 years in information security and hands-on experience with Microsoft security tools.

Qualifications

  • Bachelor’s degree or equivalent professional experience in a related field.
  • 3–5 years of information security, security engineering, security operations, cloud security, or related IT security role.
  • Hands-on experience with Microsoft security technologies such as Defender, Sentinel, Entra ID, Purview, Intune, 365 security, or Azure security services.

Responsibilities

  • Administer and optimize Microsoft security platforms and Defender suite.
  • Design and implement security policies, controls, and configurations.
  • Manage identity and access controls, including conditional access.
  • Support security operations across endpoints, email, cloud apps, and data protection.
  • Develop detection logic, alerts, dashboards, and runbooks in Sentinel and Defender.
  • Collaborate with threat response, detection engineering, infrastructure, endpoint, messaging, and compliance teams.
  • Conduct security health checks, configuration reviews, and vulnerability remediation.
  • Assist investigations involving phishing, malware, and account compromise.
  • Stay current on Microsoft security capabilities and regulatory requirements.
  • Participate in change management and incident response on-call rotations.

Skills

Defender
Sentinel
Entra ID
Purview
Intune
Azure security
Endpoint security
PowerShell
KQL
Logic Apps
Microsoft Graph
Conditional access

Education

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field

Tools

Microsoft Graph API
Logic Apps
Azure AD

Job description

Microsoft Security Engineer

King & Spalding is a leading global law firm with a commitment to excellence, innovation, and the seamless delivery of legal services. We harness innovative technology and exceptional talent to meet the complex needs of our clients in a fast‑paced and dynamic legal landscape.

We are proud of our remarkably cohesive culture, which now encompasses more than 2,500 lawyers and business professionals worldwide. We seek to attract and develop the very best talent to work with us.

King & Spalding advances leading companies’ complex legal and business interests in more than 160 countries. Collaborating across an integrated platform of transactional, litigation and regulatory talent in 24 offices globally, we work to understand and achieve our clients’ business objectives.

Key Responsibilities
  • Administer, configure, and optimize Microsoft security platforms, including Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and related security services.
  • Design and implement security policies, standards, controls, and configurations that reduce risk and improve the organization’s overall security posture.
  • Manage identity and access security controls, including creating conditional access policies.
  • Support endpoint, email, identity, cloud application, and data protection security operations through effective security policies.
  • Develop and maintain detection logic, alert rules, automation, playbooks, dashboards, and operational procedures within Microsoft Sentinel and Microsoft Defender.
  • Partner with threat response, detection engineering, infrastructure, endpoint, messaging, and compliance teams to improve prevention, detection, response, and recovery capabilities.
  • Perform security health checks, configuration reviews, control validation, and hardening activities across Microsoft 365, Azure, endpoint, identity, email, and SaaS environments.
  • Support investigations associated with phishing, malware, account compromise, suspicious authentication, data exposure, endpoint threats, and cloud-based threats.
  • Analyze logs, alerts, telemetry, indicators of compromise, and threat intelligence to identify suspicious behavior and partner with detection engineering teams create proactive alerts.
  • Stay current on Microsoft security capabilities, emerging cyber threats, industry best practices, and regulatory or compliance requirements affecting enterprise security operations.
  • Participate in change management, security projects, audit support, vulnerability remediation, and after‑hours incident response or on‑call coverage as required.
Qualifications
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent professional experience may be considered in lieu of a degree.
  • Minimum of 3–5 years of experience in information security, security engineering, security operations, cloud security, identity security, endpoint security, or a related IT security role.
  • Hands‑on experience administering or supporting Microsoft security technologies, such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, Microsoft 365 security, or Azure security services.
  • Strong understanding of cybersecurity principles, including defense‑in‑depth, least privilege, identity and access management, endpoint protection, email security, cloud security, vulnerability management, logging, monitoring, and incident response.
  • Experience configuring and maintaining security policies, conditional access rules, authentication controls, endpoint security baselines, data protection policies, and alerting rules.
  • Ability to investigate security alerts, analyze logs and telemetry, identify root cause, document findings, and recommend remediation actions.
  • Working knowledge of enterprise infrastructure, including Windows, Active Directory, Azure, Microsoft 365, networking fundamentals, DNS, email flow, authentication protocols, and cloud services.
  • Experience using scripting, query, or automation tools such as PowerShell, Kusto Query Language (KQL), Microsoft Graph, Logic Apps, or similar technologies.
  • Ability to communicate technical concepts clearly to security teams, IT stakeholders, business partners, leadership, and non‑technical audiences.
  • Strong analytical, troubleshooting, documentation, collaboration, and time‑management skills.
  • Ability to work independently and as part of a cross‑functional team in a fast‑paced enterprise environment.
  • Willingness to participate in incident response, maintenance windows, and on‑call rotations when required.
Desired Qualifications
  • Microsoft security certifications such as SC‑200, SC‑300, SC‑400, AZ‑500, MS‑102, or equivalent cloud/security certifications.
  • Experience with Microsoft Defender XDR incident queues, Advanced Hunting, secure score improvement, attack simulation, endpoint detection and response, email protection, identity protection, or cloud app security.
  • Experience building, tuning, or maintaining SIEM use cases, analytics rules, workbooks, dashboards, automation, and incident response playbooks within Microsoft Sentinel.
  • Experience supporting Microsoft Purview Data Loss Prevention, information protection, sensitivity labels, retention policies, insider risk, eDiscovery, or compliance‑related security controls.
  • Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, MITRE ATT&CK, ISO 27001, or similar industry guidance.
  • Experience with threat hunting, detection engineering, malware analysis, phishing investigation, business email compromise response, or account compromise investigation.
  • Experience with cloud platforms, SaaS security, CASB capabilities, Azure security, Google Cloud Platform security, or multi‑cloud security operations.
  • Experience working with ticketing systems, change management processes, vulnerability management platforms, and enterprise incident response workflows.
  • Strong written communication skills with the ability to produce clear technical documentation, investigation summaries, executive‑level updates, and operational procedures.
  • Demonstrated commitment to continuous learning, process improvement, operational excellence, and maintaining awareness of evolving Microsoft security features and cyber threats.
Benefits and Compensation
  • The firm offers a generous total compensation package with bonuses and raises awarded in recognition of individual merit‑based performance.
  • All full‑time Business Services employees may participate in King & Spalding’s comprehensive benefit program including health and wellness plan, life and disability insurance, flexible spending accounts and a health savings account, a 401(k) plan, profit sharing plan, and a substantial Paid Time Off (PTO) program.
Equal Opportunity

King & Spalding LLP (K&S) is committed to providing equal employment opportunity to all applicants and employees in full compliance with all state, federal, and local laws prohibiting discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, age, disability or any other status protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Microsoft Security Engineer
Microsoft Security Engineer

King & Spalding • Atlanta (GA)

On-site
USD 120,000 - 180,000
Health and wellness plan
401(k) plan
Paid time off
Privacy & Data Protection Analyst
Privacy & Data Protection Analyst

King & Spalding • Atlanta (GA)

On-site
USD 90,000 - 120,000
Health and wellness plan
Life and disability insurance
Flexible spending accounts
+4
Marketing Power Platform Specialist
Marketing Power Platform Specialist

King & Spalding LLP • Atlanta (GA)

On-site
USD 75,000 - 95,000
Health and wellness plan
401(k) plan
Paid Time Off (PTO) program
Technology Communications Specialist
Technology Communications Specialist

King & Spalding • Atlanta (GA)

On-site
USD 85,000 - 120,000
Bonuses
Comprehensive benefits
PTO
Technology Communications Strategist
Technology Communications Strategist

King & Spalding • Atlanta (GA)

On-site
USD 85,000 - 120,000
Bonuses
Comprehensive benefits
PTO
Technology Communications Specialist
Technology Communications Specialist

King & Spalding LLP • Atlanta (GA)

On-site
USD 70,000 - 90,000
Generous total compensation package
Comprehensive benefit program
401(k) plan
Business Development Coordinator
Business Development Coordinator

King & Spalding LLP • New York (NY)

On-site
USD 70,000 - 80,000
Health and wellness plan
Life and disability insurance
401(k) plan
+1
Office Manager
Office Manager

King & Spalding • Austin (TX)

On-site
USD 60,000 - 85,000
Health and wellness plan
Life and disability insurance
Flexible spending accounts
+4
Office Manager
Office Manager

King & Spalding LLP • Austin (TX), Northern (KY)

Hybrid
USD 60,000 - 90,000
Business Change Analyst
Business Change Analyst

King & Spalding • Atlanta (GA)

On-site
USD 85,000 - 110,000