Microsoft Security Automation & Incident Response Engineer - Contract Position
Magnet ForensicsAbout the role
Magnet Forensics is seeking a highly skilled Microsoft Security Automation & Incident Response Engineer to accelerate the maturity and efficiency of our security operations program.
This resource will be responsible for optimizing and integrating Microsoft's security platform, reducing manual analyst workload, automating repetitive tasks, improving detection coverage, and enhancing incident response capabilities.
The ideal candidate is a hands-on engineer with deep experience in Microsoft Sentinel, Defender XDR, automation, and modern security operations.
This is a 3-4 month contract role
What You'll Do
- Analyze existing alert triage and incident response processes
- Identify operational bottlenecks and manual activities
- Implement improvements that reduce analyst effort and response times
- Improve overall SOC efficiency and effectiveness
- Tune Microsoft Sentinel analytics rules
- Reduce false positives and alert fatigue
- Create advanced correlation rules and hunting content
- Improve quality and fidelity of security detections
- Alert enrichment
- Incident routing
- Ticket creation
- Escalation workflows
- Investigation support
- Standard response actions
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Entra ID
- Zscaler telemetry
- Existing ITSM and ticketing platforms
- Improve incident response processes
- Enhance investigation playbooks
- Develop response automation
- Create operational runbooks and documentation
Security Operations Optimization
Detection Engineering
Security Automation
Design and implement automation for:
Platform Integration
Optimize and integrate:
Incident Response Support
What We're Looking For
- 5+ years in Security Operations, Detection Engineering, or Incident Response
- Strong Microsoft Sentinel experience
- Strong Microsoft Defender suite experience
- Advanced KQL skills
- Logic Apps experience
- SOAR automation experience
- SIEM engineering experience
- Security operations workflow optimization experience
- Microsoft Security certifications
- Threat hunting experience
- Detection engineering background
- Experience integrating third-party security telemetry
- Exposure to Purview and DLP technologies
Required Qualifications
Preferred Qualifications
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s