Sentinel Defender Consultant
Sentinel Defender Consultant
Required Skills & Experience
Desirable Skills
Location: Remote
Contract Type: Contract
Duration: 2 months
Rate: £440 - £490 per day INSIDE IR35
We are seeking an experienced Sentinel Defender to support the monitoring, investigation and response to cyber security incidents within a Microsoft security environment.
The successful candidate will play a key role in protecting business-critical systems through proactive threat detection, security monitoring and incident response activities.
Working as part of a wider Security Operations or Cyber Defence team, you will leverage Microsoft Sentinel and the Microsoft Defender suite to identify, investigate and remediate security threats across complex enterprise environments.
Key Responsibilities- Monitor and investigate security alerts generated by Microsoft Sentinel and Microsoft Defender.
- Perform triage and analysis of security incidents to determine impact and appropriate response actions.
- Conduct threat hunting activities to identify suspicious or malicious activity.
- Analyse logs and security telemetry from multiple data sources.
- Create, tune and optimise Sentinel analytics rules, workbooks and detection use cases.
- Support incident response activities, including containment, eradication and recovery.
- Maintain and improve security monitoring and alerting capabilities.
- Work closely with infrastructure, cloud, networking and application teams during investigations.
- Produce clear incident reports and security documentation.
- Contribute to continuous improvement of SOC processes, playbooks and detection engineering activities.
Required Skills & Experience
- Strong hands-on experience with Microsoft Sentinel.
- Experience working with Microsoft Defender technologies, including:
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud
- Microsoft Defender for Office 365
- Experience investigating and responding to cyber security incidents.
- Strong understanding of security operations and incident response processes.
- Experience analysing Windows security events, Azure logs and cloud telemetry.
- Knowledge of cyber security frameworks, attack methodologies and threat actor tactics.
- Experience developing and tuning SIEM detections.
- Strong Kusto Query Language (KQL) skills.
- Ability to work independently within a Security Operations environment.
- Excellent analytical and problem-solving skills.
Desirable Skills
- Security Operations Centre (SOC) experience.
- Experience with Microsoft Defender XDR.
- Knowledge of MITRE ATT&CK framework.
- Experience with Azure security services.
- Experience building Sentinel workbooks and dashboards.
- Logic Apps and SOAR automation experience.
- Threat Intelligence integration experience.
- Microsoft security certifications