2 hours ago
Toronto, CanadaSenior
Responsibilities
- Design, build, and tune advanced detection logic in Microsoft Sentinel using KQL.
- Develop playbooks and workbooks to automate response actions and visualize threats.
- Lead centralized logging strategy and optimize Log Analytics workspaces for data quality, cost, and performance.
- Own Microsoft Defender for Cloud and drive remediation of security recommendations.
- Partner with infrastructure and solution architects to embed security into Azure landing zones and CI/CD pipelines.
- Secure Azure networking, IAM, compute services, AKS, and containerized workloads while identifying configuration drift.
- Translate security objectives into technical roadmaps, lead initiatives through delivery, and report progress to leadership.
Requirements
- Deep practical experience with the Azure security stack, including Microsoft Sentinel, Defender for Cloud, and the Microsoft Defender portal.
- Mastery of KQL for threat hunting and detection rule creation.
- Experience designing scalable logging architectures using Diagnostic settings, Event Hubs, and Log Analytics.
- Expertise in Azure-native network security, including Azure Firewall, Web Application Firewall, and Private Link or Private Endpoints.
- Experience securing Azure Kubernetes Service and containerized workloads with Defender for Containers and admission controllers.
- Ability to drive initiatives from concept through delivery with minimal supervision and communicate technical security risks in business terms.
Benefits
- Global hybrid policy requiring two days per week in the office and permitting remote work on other days.
- Benefits vary by country and may include health and dental care, time off, and Group RRSP/TFSA for Toronto employees.
- Employees are eligible for an annual discretionary bonus.
