Widenet Consulting logo

SR. CYBERSECURITY ENGINEER, CLOUD AND INCIDENT RESPONSE

Widenet Consulting

  • Seattle, Washington
  • 3 days ago
  • Contractor

Highlights

Lead and support investigations across cloud, identity, endpoint, email, and SaaS, including account compromise, data exfiltration, insider risk, and business email compromise. This position will help strengthen the cloud security posture, mature incident response capabilities, and advance data security and zero-trust initiatives.

Numbers & Facts

LocationSeattle, Washington
Job TypeContractor
IndustryStaffing/Employment Agencies
Company Size50 to 99 employees
Year Founded2009
Websitehttp://www.widenet-consulting.com/

Description

Job Description:
Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.

This position will help strengthen the cloud security posture, mature incident response capabilities, and advance data security and zero-trust initiatives.

Responsibilities
Cloud security:
– Harden Azure and multi-cloud environments against recognized benchmarks and cloud security posture findings
– Remediate Defender for Cloud findings and drive measurable secure score improvement
– Implement workload protection, configuration baselines, and infrastructure-as-code security checks
– Address cloud identity and entitlement risk, including overprivileged roles, service principals, and standing access

Incident response:
– Enhance and operationalize incident response playbooks aligned to NIST SP 800-61
– Lead and support investigations across cloud, identity, endpoint, email, and SaaS, including account compromise, data exfiltration, insider risk, and business email compromise
– Perform containment, eradication, recovery, evidence preservation, and post-incident reporting
– Coordinate with the managed detection and response provider on escalation quality, handoff, and case closure
– Design and facilitate tabletop exercises and translate findings into control improvements

SIEM optimization and detection engineering:
– Tune Microsoft Sentinel for signal quality and cost efficiency, including connector selection, ingestion tiering, and table-level retention decisions
– Author and maintain analytic rules and hunting queries in KQL
– Map detection coverage to MITRE ATT&CK and close identified gaps
– Reduce false positive volume and improve alert enrichment and automation through SOAR playbooks

Data security and DLP:
– Design, deploy, and tune Microsoft Purview DLP policies across email, endpoint, SharePoint, OneDrive, Teams, and cloud apps
– Implement sensitivity labels, auto-labeling, and data classification at scale
– Operate Insider Risk Management and support eDiscovery and investigative requests
– Drive DLP findings to closure through policy change, access revocation, or corrective action, not just alerting

Zero trust:
– Advance zero trust maturity across identity, device, network, application, and data pillars
– Implement and refine conditional access, privileged identity management, device compliance, and least privilege access models
– Support segmentation and egress control initiatives

Required Qualifications
– 7+ years in security engineering or security operations
– Deep hands-on Microsoft security stack experience: Sentinel, Defender XDR, Defender for Cloud, Entra ID, Intune
– Direct, demonstrable Microsoft Purview experience across DLP, sensitivity labels, and Insider Risk Management
– Strong KQL authoring ability, including detection development and investigative hunting
– Demonstrated incident response leadership on real incidents, not tabletop only
– Azure cloud security depth, including identity, networking, and workload protection
– PowerShell and Microsoft Graph API automation
– Clear written communication for both technical peers and executive audiences

Preferred
– Experience in a lean security team where the role spans engineering and operations
– Familiarity with Palo Alto Networks, Tanium, and CASB or SSPM platforms
– Digital forensics experience, including cloud and M365 artifact analysis
– Experience working alongside an MXDR or managed SOC provider
– Certifications: AZ-500, SC-200, SC-400, SC-100, GCIH, GCFA, CISSP

Pay Range: $85.00 – $95.00 per hour, depending upon experience.
Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.
 
 

About Company

Whether you are a candidate looking for a new opportunity or an organization looking for talent, when you work with WideNet Consulting, you can be confident that you will receive an unequaled experience. As a leading technology consulting and recruitment firm, WideNet has built an outstanding reputation of consistently bringing together professionals, who are the best in their field, with exceptional opportunities at the finest, most dynamic companies.

Our strengths:

We understand the challenges of business and organization management. Our team has helped departments and companies identify specific challenges and solutions, then built road maps to a smoother business model.

We know technology project management and assist on projects at ANY point in the process.

We build our dream team of Clients & Candidates carefully and purposefully, and then interact with them intensely and often. The journey ends with the perfect fusion of our Client's business objectives and our Candidate's expertise working together in perfect harmony.

We use our proprietary recruiting strategy and process, WideScreen™ to match Candidate expertise to Client needs and culture, consistently exceeding expectations. We work to deliver the right person for the need AND the company.

We conduct business with honesty, integrity, and dedication. We do what we say we're going to do. We follow-up and follow through until the best candidate is matched to the right opportunity.

We are not a volume shop. We are completely focused on creating the best possible fit between our Client's business objectives and our Candidate's expertise, every time.

We help our Clients match their technology solutions with current staff configurations, then provide the tools, experience and resources to develop targeted Information Technology initiatives that improve productivity and enhance systems management.

Similar Jobs

See more jobs