Sr. Cybersecurity Engineer, Cloud and Incident Response

WideNet Consulting Group

Seattle (WA)

On-site

USD 243,560,000 - 272,214,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401K
Employee Assistance Program
Sick time

Job summary

WideNet Consulting Group in Seattle is seeking a Sr. Cybersecurity Engineer specializing in Cloud and Incident Response to strengthen cloud security posture and incident response capabilities.

The role requires onsite work 2-3 days per week with potential PST remote options. You will lead cloud security hardening, SIEM optimization, DLP, and zero-trust initiatives, coordinating with MSPs and internal teams.

Qualifications

  • 7+ years in security engineering or security operations.
  • Direct, demonstrable Microsoft Purview experience across DLP, sensitivity labels, and Insider Risk Management.
  • Deep hands-on Microsoft security stack experience: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune.
  • Strong KQL authoring ability, including detection development and investigative hunting.
  • Clear written communication for both technical peers and executive audiences.
  • Azure cloud security depth, including identity, networking, and workload protection.

Responsibilities

  • Harden Azure and multi-cloud environments against benchmarks and cloud security posture findings.
  • Remediate Defender for Cloud findings and drive secure score improvement.
  • Implement workload protection, configuration baselines, and IaC security checks.
  • Address cloud identity and entitlement risk, including overprivileged roles and service principals.
  • Enhance and operationalize incident response playbooks aligned to NIST SP 800-61.
  • Lead investigations across cloud, identity, endpoint, email, and SaaS; coordinate with MSP on escalation and handoff.
  • Tune Microsoft Sentinel for signal quality, cost efficiency, and retention; develop KQL rules and hunting queries.
  • Map detection coverage to MITRE ATT&CK and close gaps; reduce false positives with SOAR automation.
  • Design and deploy Purview DLP policies; implement sensitivity labels and data classification at scale.
  • Advance zero trust maturity across identity, device, network, application, and data pillars.

Skills

Security engineering
KQL
PowerShell
Azure security
Security operations
Executive communication

Tools

Sentinel
Defender XDR
Defender for Cloud
Entra ID
Intune
Purview
Microsoft Graph API
SOAR

Job description

Sr. Cybersecurity Engineer, Cloud and Incident Response

Job Description:

Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.

This position will help strengthen the cloud security posture, mature incident response capabilities, and advance data security and zero-trust initiatives.

Responsibilities
Cloud security:
– Harden Azure and multi-cloud environments against recognized benchmarks and cloud security posture findings
– Remediate Defender for Cloud findings and drive measurable secure score improvement
– Implement workload protection, configuration baselines, and infrastructure-as-code security checks
– Address cloud identity and entitlement risk, including overprivileged roles, service principals, and standing access

Incident response:
– Enhance and operationalize incident response playbooks aligned to NIST SP 800-61
– Lead and support investigations across cloud, identity, endpoint, email, and SaaS, including account compromise, data exfiltration, insider risk, and business email compromise
– Perform containment, eradication, recovery, evidence preservation, and post-incident reporting
– Coordinate with the managed detection and response provider on escalation quality, handoff, and case closure
– Design and facilitate tabletop exercises and translate findings into control improvements

SIEM optimization and detection engineering:
– Tune Microsoft Sentinel for signal quality and cost efficiency, including connector selection, ingestion tiering, and table-level retention decisions
– Author and maintain analytic rules and hunting queries in KQL
– Map detection coverage to MITRE ATT&CK and close identified gaps
– Reduce false positive volume and improve alert enrichment and automation through SOAR playbooks

Data security and DLP:
– Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps
– Implement sensitivity labels, auto-labeling, and data classification at scale
– Operate Insider Risk Management and support eDiscovery and investigative requests
– Drive DLP findings to closure through policy change, access revocation, or corrective action, not just alerting

Zero trust:
– Advance zero trust maturity across identity, device, network, application, and data pillars
– Implement and refine conditional access, privileged identity management, device compliance, and least privilege access models
– Support segmentation and egress control initiatives

Required Qualifications
– 7+ years in security engineering or security operations
– Deep hands-on Microsoft security stack experience: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune
– Direct, demonstrable Microsoft Purview experience across DLP, sensitivity labels, and Insider Risk Management
– Strong KQL authoring ability, including detection development and investigative hunting
– Demonstrated incident response leadership on real incidents, not tabletop only
– Azure cloud security depth, including identity, networking, and workload protection
– PowerShell and Microsoft Graph API automation
– Clear written communication for both technical peers and executive audiences

Preferred
– Experience in a lean security team where the role spans engineering and operations
– Familiarity with Palo Alto Networks, Tanium, and CASB or SSPM platforms
– Digital forensics experience, including cloud and M365 artifact analysis
– Experience working alongside an MXDR or managed SOC provider
– Certifications: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, CISSP

Pay Range:$85.00 – $95.00 per hour, depending upon experience.
Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.

Accepted file types: doc, docx, pdf, Max. file size: 2 MB.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Engineer New United States - Remote
Cloud Security Engineer New United States - Remote

CyberSheath Services International, LLC • Northern (KY)

Hybrid
USD 85,000 - 100,000
Senior Cloud & Incident Response Security Engineer
Senior Cloud & Incident Response Security Engineer

WideNet Consulting Group • Seattle (WA)

On-site
USD 243,560,000 - 272,214,000
Health benefits
401K
Employee Assistance Program
+1
Journeyman Cloud Security Engineer (Q Clearance)
Journeyman Cloud Security Engineer (Q Clearance)

Jobless • Washington, Northern (KY)

Hybrid
USD 120,000 - 170,000
144 hours PTO
11 holidays
85% health insurance premium covered
+2
Journeyman Cloud Security Engineer (Q Clearance)
Journeyman Cloud Security Engineer (Q Clearance)

ShorePoint • Washington, Northern (KY)

Hybrid
USD 150,000 - 210,000
PTO 144 hours
11 holidays
Insurance premium coverage 85%
+4
Cloud Security Engineer
Cloud Security Engineer

Triwill Group • United States

On-site
USD 86,000 - 112,000
Competitive base salary
Medical, dental, vision insurance
401(k) retirement plan
+2
Cloud Security Engineer
Cloud Security Engineer

Highbrow LLC • Marietta (GA), Omaha (NE), Alpharetta (GA), Berkeley Heights (NJ)

Hybrid
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Security Operations Center Cloud Engineer
Security Operations Center Cloud Engineer

Lakeview Loan Servicing • Coral Gables (FL)

Remote
USD 165,000 - 175,000
Annual bonus
Remote work flexibility
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000