Incident Coordinator & Threat Hunting Engineer
Drees & SommerAbout the role
Company Description
Creating a future worth living for future generations gets us out of bed every morning. Depending on the project, we are consultants, implementers, or both for sustainable, innovative and economical solutions for real estate, industry, energy and infrastructure. Our more than 6,500 employees at 70 locations worldwide support our customers in interdisciplinary teams. Our thinking is both visionary and realistic. We work independently and as part of a team. With passion and the latest technologies. We unite. Join us at Dreso and let’s create a world we want to live in.
Job Description
We are seeking a dedicated Incident Coordinator & Threat Hunting Engineer to join our team and help protect and continuously improve our organization’s security posture. In this role, you will monitor and defend our systems in real-time, lead incident response and threat hunting efforts, and drive strategic security enhancements. You’ll play a critical part in safeguarding company data and services from cyber threats. This is an exciting opportunity for a mid-level professional who enjoys both hands-on security operations and contributing to long-term security strategy. If you thrive on solving complex security challenges – from rapidly responding to incidents to proactively hunting for hidden threats – and want to make a real impact on our security maturity, we’d love to hear from you.
Key Responsibilities:
Security Monitoring & Operations:
- Monitor Security Information and Event Management (SIEM) dashboards and alerts to identify and analyze potential threats in real time using Microsoft Sentinel (Log Analytics, KQL, Analytic Rules, Workbooks) and Microsoft 365 Defender (Defender XDR Incidents, Advanced Hunting). Include Microsoft Purview DLP alerts where applicable.
- Perform in-depth analysis of suspicious activities, anomalies, and malware indicators; triage security events and escalate incidents as appropriate with KQL, Microsoft 365 Defender Advanced Hunting, Entra ID (Azure AD) sign-in/audit logs, and Sentinel Investigation graphs.
- Conduct regular vulnerability assessments and support penetration testing efforts to uncover security weaknesses, working with IT teams to remediate findings via Microsoft Defender Vulnerability Management (MDVM) and Defender for Cloud recommendations; third-party tools may supplement as needed.
- Support patch management by tracking critical vulnerabilities and verifying that systems and applications are updated in a timely manner to reduce exposure using Intune/Windows Update for Business, Azure Update Manager, and Defender for Cloud VM/Container hardening guidance.
Incident Response:
- Investigate and contain cybersecurity incidents or breaches – coordinate actions such as evidence collection, digital forensic analysis (disk, memory, logs), and system recovery to minimize damage leveraging Microsoft Defender XDR (Defender for Endpoint/Office 365/Identity/Cloud Apps), Microsoft Sentinel, MDE Live Response, and Entra ID.
- Lead post-incident analysis to determine root causes and create incident reports with actionable recommendations to prevent recurrence.
- Develop and maintain incident response playbooks and procedures, ensuring they stay up-to-date with emerging threats and lessons learned from past events (e.g., Sentinel Playbooks with Logic Apps, Automation Rules, and MDE custom detections).
- Coordinate with IT infrastructure, development, and business teams during incident response to ensure effective communication and swift resolution of issues.
Threat Hunting & Digital Forensics:
- Proactively hunt for threats lurking in our networks and systems that may evade automated defenses, by analyzing security logs, network traffic, and endpoint data for signs of malicious activity across Microsoft Sentinel, Defender XDR, and Microsoft Purview audit logs.
- Develop hypotheses of potential attacker tactics (using frameworks like MITRE ATT&CK) and investigate those leads to uncover stealthy threats; create custom detection queries or scripts to support hunting operations (KQL in Sentinel and Advanced Hunting in Microsoft 365 Defender; create Sentinel Analytic Rules and custom detections).
- Perform deep-dive forensic analysis on digital evidence (such as malware samples, system images, memory dumps) to extract indicators of compromise and understand attack techniques using MDE investigation packages, Live Response file collection, and appropriate memory/disk tools; integrate IOCs into Sentinel and Defender.
- Continuously collaborate with the SOC team to integrate threat hunting findings into improved monitoring rules and to enhance
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s