Jobs and Careers
MA

Microsoft Security Automation & Incident Response Engineer - Contract Position

Magnet Forensics
United States, United Statesfull_timeVerifiedPosted 13 Jul 2026

About the role

Who We Are; What We Do; Where We’re Going
 
Magnet Forensics is a global leader in the development of digital investigative software that acquires, analyzes, and shares evidence from computers, smartphones, tablets, and IoT-related devices. We are continually innovating so our customers can deploy advanced and effective tools to protect their companies, communities, and countries.
 
Serving thousands of customers globally, our solutions are playing a crucial role in modernizing digital investigations, helping investigators fight crime, protect assets, and guard national security.
 
With employees based around the world, Magnet Forensics has been expanding our global presence. As a part of Magnet Forensics, you can expect to make a difference in the world, no matter what role you play. You’ll be supported through learning and development, not to mention an incredible team with unbelievable talent and integrity.
 
If you think you would be the right person to join our team working towards this goal, we would love to hear from you! 

Role Summary
 

Magnet Forensics is seeking a highly skilled Microsoft Security Automation & Incident Response Engineer to accelerate the maturity and efficiency of our security operations program.

This resource will be responsible for optimizing and integrating Microsoft's security platform, reducing manual analyst workload, automating repetitive tasks, improving detection coverage, and enhancing incident response capabilities.

The ideal candidate is a hands-on engineer with deep experience in Microsoft Sentinel, Defender XDR, automation, and modern security operations.

This is a 3-4 month contract role

What You'll Do

    Security Operations Optimization

    • Analyze existing alert triage and incident response processes
    • Identify operational bottlenecks and manual activities
    • Implement improvements that reduce analyst effort and response times
    • Improve overall SOC efficiency and effectiveness
    • Detection Engineering

      • Tune Microsoft Sentinel analytics rules
      • Reduce false positives and alert fatigue
      • Create advanced correlation rules and hunting content
      • Improve quality and fidelity of security detections
      • Security Automation

        Design and implement automation for:

        • Alert enrichment
        • Incident routing
        • Ticket creation
        • Escalation workflows
        • Investigation support
        • Standard response actions
        • Platform Integration

          Optimize and integrate:

          • Microsoft Sentinel
          • Microsoft Defender XDR
          • Microsoft Defender for Endpoint
          • Microsoft Defender for Identity
          • Microsoft Defender for Cloud Apps
          • Entra ID
          • Zscaler telemetry
          • Existing ITSM and ticketing platforms
          • Incident Response Support

            • Improve incident response processes
            • Enhance investigation playbooks
            • Develop response automation
            • Create operational runbooks and documentation

What We're Looking For

    Required Qualifications

    • 5+ years in Security Operations, Detection Engineering, or Incident Response
    • Strong Microsoft Sentinel experience
    • Strong Microsoft Defender suite experience
    • Advanced KQL skills
    • Logic Apps experience
    • SOAR automation experience
    • SIEM engineering experience
    • Security operations workflow optimization experience
    • Preferred Qualifications

      • Microsoft Security certifications
      • Threat hunting experience
      • Detection engineering background
      • Experience integrating third-party security telemetry
      • Exposure to Purview and DLP technologies
Indicators of Success
 
We’re looking for someone who checks off most, but not all, of the boxes listed in “skills and experiences”.  It’s more important to us to find candidates who can display indicators of success through skills they have developed and experiences they have been a part of, than to find folks who have “been there, done that”.  We want to be part of your development journey, and we’ll learn as much from you as you learn from us. 
 
How We Work<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Magnet Forensics

View company profile →