Sr. Remediation Specialist (AIR)

LevelBlue

United States

On-site

USD 150,000 - 210,000

Full time

13 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

LevelBlue is seeking a Senior Cybersecurity Engineering Consultant to lead client-facing engagements across SIEM engineering, Microsoft Defender XDR integration, and security operations optimization. You will own design and build work on live engagements, including analytics, detection logic, security integrations, and client-ready deliverables.

You will run workshops, provide SME-level guidance for both technical and non-technical stakeholders, and produce artifacts that clients can operate and

Qualifications

  • Experience delivering client-focused engagements in security engineering.
  • Hands-on Microsoft Sentinel engineering in production.
  • Experience producing detection design records (AIR DDRs).
  • Hands-on Microsoft Defender XDR in a SOC context.
  • Hands-on Microsoft Purview configuration in security/compliance context.

Responsibilities

  • Lead SIEM design and implementation on greenfield SOC builds and brownfield optimization: data-source onboarding, analytics rules, hunting queries, automation rules and playbooks, workbooks, incident process alignment and use-case documentation.
  • Design and build custom detection content aligned to the client’s threat profile and telemetry.
  • Integrate and operationalize Microsoft Defender XDR.
  • Assess requirements and advise on best-practice implementation and configuration for Microsoft Purview, Entra ID, Defender for Cloud, Azure security.
  • Build practical automation to improve response quality: Sentinel automation rules, Logic Apps, analyst actions.
  • Produce client-ready design and build artifacts: use case catalog, automation/playbook designs, implementation plans, gap analyses, tactical roadmaps.
  • Facilitate workshops and discussion sessions; capture requirements, decisions, risks, and scope changes.
  • Support pre-sales with effort estimates, technical scope, and solution shaping.

Skills

Client workshops
Microsoft Sentinel
Microsoft Defender XDR
Microsoft Purview
KQL

Tools

Microsoft Sentinel
Microsoft Defender XDR
Microsoft Purview
KQL

Job description

About The Role

LevelBlue’s Professional Services Organization is hiring a Senior Cybersecurity Engineering Consultant for client-facing delivery across

LevelBlue’s Professional Services Organization is hiring a Senior Cybersecurity Engineering Consultant for client-facing delivery across SIEM engineering, Microsoft security advisory and implementation, and security operations optimization. This is not an analyst role. You will own design and build work on live engagements: analytics, detection logic, security integrations, technical advisory, and client-ready delivery artifacts. You will run workshops, provide SME-level guidance for technical and non-technical stakeholders, and leave clients with something they can operate. You will operate independently and in mixed teams, manage your own work across concurrent clients, and improve practice proposals and delivery assets.

Role Expectations / Key Responsibilities

Engagement Delivery

  • Deliver engagements across a range of service lines. Lead SIEM design and implementation on greenfield SOC builds and brownfield optimization: data-source onboarding (e.g., telemetry analysis, ingestion design, parsing and normalization, custom connectors), analytics rules, hunting queries, automation rules and playbooks, workbooks, incident process alignment, and use-case documentation.
  • Design and build custom detection content aligned to the client’s threat profile and available telemetry.
  • Integrate and operationalize Microsoft Defender XDR.
  • Assess requirements and advise on best-practice implementation and configuration for Microsoft Purview, Entra ID, Defender for Cloud, Azure security, Copilot. Deliver guided implementation and hands-on configuration when required.
  • Microsoft Purview: you can discover client requirements, recommend a target configuration, and explain how to implement it (information protection, DLP, audit, or related controls as relevant). Hands-on build is desirable.
  • Build practical automation where it improves response quality: Sentinel automation rules, Logic Apps, and analyst response actions.
  • Produce client-ready design and build artifacts: for example, use case catalog, automation/playbook designs, implementation plans, gap analyses, tactical maturity roadmaps with executive summaries.
  • Facilitate workshops and discussion sessions; capture requirements, decisions, risks, and scope changes.
  • Support pre-sales with effort estimates, technical scope, and solution shaping.
Required Experience & Qualifications
  • Senior consulting or professional‑services delivery (not only an internal SOC or engineering seat): you have owned client workshops around business requirements and use case discovery, engagement scope, and signed‑off deliverables.
  • Hands‑on Microsoft Sentinel engineering in production, including analytic rule design and build, query tuning and optimization, false‑positive reduction, and use‑case operationalization.
  • Experience producing detection design records (AIR DDRs): our use case notes covering use case scenarios, data sources, KQL, tuning notes.
  • Hands‑on Microsoft Defender XDR (at least Defender for Endpoint plus one of Identity / Office / Cloud Apps) in a detection or SOC‑integration context.
  • Hands‑on Microsoft Purview configuration in a security or compliance context connected to monitoring or control design.
Useful Experience

Experience in any of the following is a plus and may be used on engagements; it does not replace SIEM engineering or Microsoft security delivery.

  • Firewall / network security configuration reviews (policy quality, logging to SIEM, segmentation relevant to detections).
  • Active Directory security reviews (beyond detections): privileged access, delegation, hardening, hybrid identity.
  • Azure security reviews (beyond Defender for Cloud / Sentinel): landing‑zone and control‑plane hygiene.
  • AWS security reviews or multi‑cloud posture work.
  • Splunk or SentinelOne (working knowledge).
  • Broader control reviews that feed a security operations or threat detection and response roadmap.
Certifications (desirable)
  • Most relevant: SC-200; SC-500 (AZ-500)
  • Also useful: SC-100, SC-300, SC-400; Splunk ES Admin or Splunk Architect; GIAC detection/IR (e.g. GCIA, GCIH); CISSP
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 120,000 - 190,000
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)
Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

Trustwave • United States

On-site
USD 140,000 - 190,000
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)

LevelBlue • United States

On-site
USD 120,000 - 160,000
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 120,000 - 180,000
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)
Snr Cybersecurity Consultant Engineer (Architecture, Infrastructure and Remediation)

Trustwave • United States

On-site
USD 140,000 - 190,000
Senior SIEM & Defender XDR Engineering Consultant
Senior SIEM & Defender XDR Engineering Consultant

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 120,000 - 190,000
Sr. SIEM Engineering Consultant
Sr. SIEM Engineering Consultant

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 180,000
Senior Cybersecurity Engineering Consultant - SIEM & XDR
Senior Cybersecurity Engineering Consultant - SIEM & XDR

LevelBlue • United States

On-site
USD 150,000 - 210,000
Senior Cybersecurity Consultant — SIEM & XDR Delivery
Senior Cybersecurity Consultant — SIEM & XDR Delivery

Trustwave • United States

On-site
USD 140,000 - 190,000
Security Engineer (Hybrid)
Security Engineer (Hybrid)

B5 Recruiting • Washington

On-site
USD 120,000 - 180,000