Sentinel Defender Consultant
Location: Remote
Contract Type: Contract
Duration: 2 months
Rate: £440 - £490 per day INSIDE IR35
Overview
We are seeking an experienced Sentinel Defender to support the monitoring, investigation and response to cyber security incidents within a Microsoft security environment.
The successful candidate will play a key role in protecting business-critical systems through proactive threat detection, security monitoring and incident response activities.
Working as part of a wider Security Operations or Cyber Defence team, you will leverage Microsoft Sentinel and the Microsoft Defender suite to identify, investigate and remediate security threats across complex enterprise environments.
Key Responsibilities
Monitor and investigate security alerts generated by Microsoft Sentinel and Microsoft Defender.
Perform triage and analysis of security incidents to determine impact and appropriate response actions.
Conduct threat hunting activities to identify suspicious or malicious activity.
Analyse logs and security telemetry from multiple data sources.
Create, tune and optimise Sentinel analytics rules, workbooks and detection use cases.
Support incident response activities, including containment, eradication and recovery.
Maintain and improve security monitoring and alerting capabilities.
Work closely with infrastructure, cloud, networking and application teams during investigations.
Produce clear incident reports and security documentation.
Contribute to continuous improvement of SOC processes, playbooks and detection engineering activities.
Required Skills & Experience
Strong hands-on experience with Microsoft Sentinel.
Experience working with Microsoft Defender technologies, including:
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud
Microsoft Defender for Office 365
Experience investigating and responding to cyber security incidents.
Strong understanding of security operations and incident response processes.
Experience analysing Windows security events, Azure logs and cloud telemetry.
Knowledge of cyber security frameworks, attack methodologies and threat actor tactics.
Experience developing and tuning SIEM detections.
Strong Kusto Query Language (KQL) skills.
Ability to work independently within a Security Operations environment.
Excellent analytical and problem-solving skills.
Desirable Skills
Security Operations Centre (SOC) experience.
Experience with Microsoft Defender XDR.
Knowledge of MITRE ATT&CK framework.
Experience with Azure security services.
Experience building Sentinel workbooks and dashboards.
Logic Apps and SOAR automation experience.
Threat Intelligence integration experience.
Microsoft security certifications