5+ years experience configuring, deploying and maintaining and optimizing Azure Security cloud native tools:
Azure Sentinel including User and Entity Behavior Analytics (UEBA), and Security Orchestration, Automation and Response (SOAR)
Azure Defender including Endpoint Detection and Response (EDR) and Cloud Security Posture Management (CSPM) and Azure Cloud Workload Protection (CWPP).
Azure Purview (Data Loss Prevention)
Configure rules for real-time alerting in SIEM tool for events;
Provide security monitoring including log aggregation/centralization, correlation, and alerting of security events and incidents;
Review and analyze audit records weekly for identified unusual activity and provide evidence of review and/or findings;
Conduct account reviews;
Determine auditable events and review on an annual basis;
Support incident response activities;
Microsoft Azure Security related certifications are strongly recommended
5+ years experience implementing security controls and policies, managing access to data, and monitoring threats to ensure that data, applications, infrastructure, and networks are protected.
5 + Experence with Security Assessment and Authorization (ATO) process
Support audit data calls
Bachelors Degree and a minimum 5 years experience. Additional years of experience maybe accepted in lieu of the degree.
Ability to acquire a Public Trust Background investigation
Certified in industry recognized areas such as CISSP, CISA, or CISM
Preferred Technical and Professional Expertise
Excellent organization, collaboration, project management, and team leadership skills
Strong communication skills and experience creating and delivering compliance status and metrics briefings to senior leadership
2+ years experience coordinating across security, IT operations, audit, and development groups to achieve security outcomes