Azure Cloud Sentinel Engineer
Experis · Marietta, GA · 2 wk ago
On-siteEngineeringContract
Our client, a Fortune 500 financial technology company, is hiring an Azure Sentinel Engineer to support a federal government program in an Azure Government (GovCloud) environment. This is a hands-on detection engineering role focused on building security monitoring capabilities, not triaging alerts. The program operates under FedRAMP and FISMA, so security work is measured against real federal controls.
Responsibilities
- Design, implement, and maintain Microsoft Sentinel SIEM/SOAR
- Onboard and manage security data sources into Azure Log Analytics — Syslog, CEF, REST APIs, threat intelligence feeds
- Write and tune KQL queries, analytics rules, alerts, and workbooks
- Build automated response playbooks with Azure Logic Apps
- Perform threat hunting, incident investigation, and response with SOC teams
- Implement Azure security controls aligned to Zero Trust
- Assess vulnerabilities, analyze attacker TTPs, and drive remediation
- Support cloud security governance, compliance, and audit activity across FedRAMP and FISMA requirements
- Provide security architecture guidance on cloud security strategy
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
- 5+ years cybersecurity experience with substantial hands-on Microsoft Sentinel administration and engineering
- Hands-on, current experience (within the last 12 months) with:
- Microsoft Sentinel, Azure Log Analytics, Kusto Query Language (KQL), Azure Logic Apps, Microsoft Defender suite, Azure security and identity services
- Privileged Access Management (PAM) and Identity and Access Management concepts
- CI/CD security and application security scanning
- Configuring and securing enterprise Azure environments
- Working knowledge of Zero Trust architecture and cloud security best practices
- US Citizen or Green Card holder with 3+ years continuous US residence and work history (no offshore work within that window)
- Federal background check required (allow 4–8 weeks)
- Willing and able to work onsite in Marietta, GA five days per week
- Open to converting to full-time employment with the client
Preferred Qualifications
- Azure Government (GovCloud) experience
- FISMA, FedRAMP, and NIST 800-53 compliance experience
- Certifications: SC-200, AZ-500, SC-100, CISSP, CCSP — current, not lapsed
- Microsoft Defender XDR: Defender for Endpoint, Office 365, Identity, Cloud Apps
- Data protection: Microsoft Purview, MIP, DLP, Key Vault
- Identity: Entra ID, PIM, Conditional Access, Azure Lighthouse
- Experience migrating an organization from Splunk, QRadar, ArcSight, or LogRhythm onto Sentinel
- Prior work with government clients, auditors, and executive stakeholders
Schedule
- 100% onsite, 5 days/week in Marietta, GA
- 1-Year Contract to Hire
About the Opportunity
Greenfield security work on a federal program with real mission weight, on a team that is actively growing. Contract to hire with a clear path to permanent employment.