Skip to content

Open nowPosted 15 days ago

Sr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)

twh43 open roles

Where
United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr. Cybersecurity Engineering Consultant - SIEM/Microsoft (AIR)twh · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on twh's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 15 days ago

The posting

About the Role 

LevelBlue’s Professional Services Organization is hiring a Senior Cybersecurity Engineering Consultant for client-facing delivery across SIEM engineering, Microsoft security advisory and implementation, and security operations optimization. This is not an analyst role. You will own design and build work on live engagements: analytics, detection logic, security integrations, technical advisory, and client-ready delivery artifacts. You will run workshops, provide SME-level guidance for technical and non-technical stakeholders, and leave clients with something they can operate. You will operate independently and in mixed teams, manage your own work across concurrent clients, and improve practice proposals and delivery assets. 

Role Expectations / Key Responsibilities 

Engagement Delivery 

Deliver engagements across a range of service lines. Lead SIEM design and implementation on greenfield SOC builds and brownfield optimization: data-source onboarding (e.g., telemetry analysis, ingestion design, parsing and normalization, custom connectors), analytics rules, hunting queries, automation rules and playbooks, workbooks, incident process alignment, and use-case documentation. 

Design and build custom detection content aligned to the client’s threat profile and available telemetry. 

Integrate and operationalize Microsoft Defender XDR. 

Assess requirements and advise on best-practice implementation and configuration for Microsoft Purview, Entra ID, Defender for Cloud, Azure security, Copilot. Deliver guided implementation and hands-on configuration when required.   

Microsoft Purview: you can discover client requirements, recommend a target configuration, and explain how to implement it (information protection, DLP, audit, or related controls as relevant). Hands-on build is desirable. 

Build practical automation where it improves response quality: Sentinel automation rules, Logic Apps, and analyst response actions. 

Produce client-ready design and build artifacts: for example, use case catalog, automation/playbook designs, implementation plans, gap analyses, tactical maturity roadmaps with executive summaries.  

Facilitate workshops and discussion sessions; capture requirements, decisions, risks, and scope changes. 

Support pre-sales with effort estimates, technical scope, and solution shaping. 

Experience & Qualifications 

Required 

Senior consulting or professional-services delivery (not only an internal SOC or engineering seat): you have owned client workshops around business requirements and use case discovery, engagement scope, and signed-off deliverables. 

Hands-on Microsoft Sentinel engineering in production, including analytic rule design and build, query tuning and optimization, false-positive reduction, and use-case operationalization. 

Experience producing detection design records (AIR DDRs): our use case notes covering use case scenarios, data sources, KQL, tuning notes. 

Hands-on Microsoft Defender XDR (at least Defender for Endpoint plus one of Identity / Office / Cloud Apps) in a detection or SOC-integration context. 

Hands-on Microsoft Purview configuration in a security or compliance context connected to monitoring or control design. 

Useful 

Experience in any of the following is a plus and may be used on engagements; it does not replace SIEM engineering or Microsoft security delivery. 

Firewall / network security configuration reviews (policy quality, logging to SIEM, segmentation relevant to detections). 

Active Directory security reviews (beyond detections): privileged access, delegation, hardening, hybrid identity. 

Azure security reviews (beyond Defender for Cloud / Sentinel): landing-zone and control-plane hygiene. 

AWS security reviews or multi-cloud posture work. 

Splunk or SentinelOne (working knowledge). 

Broader control reviews that feed a security operations or threat detection and response roadmap. 

Certifications (desirable) 

Most relevant: SC-200; SC-500 (AZ-500) 

Also useful: SC-100, SC-300, SC-400; Splunk ES Admin or Splunk Architect; GIAC detection/IR (e.g. GCIA, GCIH); CISSP 

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against twh's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on twh's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    twh's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.