Washington, DC30+ days ago
Preferred Qualifications: Microsoft SC‑200 (Security Operations Analyst) - highly preferred• Microsoft SC‑100 (Cybersecurity Architect)• Microsoft AZ‑500 (Azure Security Engineer)• Microsoft SC‑300 (Identity and Access Administrator)• Experience architecting multi‑tenant or multi‑workspace Sentinel environments• Experience with Sentinel content hub solutions and custom content development• Proficiency with Microsoft Defender for Cloud workload protection across Azure, AWS, and GCP• Experience developing Logic Apps and Power Automate flows for security automation• Proficiency with Splunk for monitoring, alerting, and threat hunting• Knowledge of Microsoft Azure/Entra ID access and identity management (Conditional Access, PIM, Identity Protection)• Experience with digital forensics tools (Autopsy, Magnet Forensics, KAPE, CyLR, Volatility, Zimmerman tools)• Experience with ServiceNow SOAR for automated ticketing and response• Proficiency in Python, PowerShell, and Bash for automation and tool development• Ability to perform static/dynamic malware analysis and reverse engineering• Experience integrating cyber threat intelligence and IOC-based hunting into Sentinel TI module• Experience leading purple team exercises and translating findings into actionable detections• Additional preferred certifications: Microsoft: SC‑200, SC‑100, AZ‑500, SC‑300, SC‑900. Education & Experience• Bachelor's degree and a minimum of 5 years of cybersecurity experience, OR a high school diploma and 9 years of cybersecurity experience.• Minimum 3 years of hands-on experience implementing and operating Microsoft Sentinel (workspace deployment, analytics rule development, workbook creation, playbook automation).•