Apply Now

Please mention DailyRemote when applying

1. M365 E5 Security Administration & Engineering

  • Identity & Access (Entra ID): Configure and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection rules.
  • Endpoint Security (Microsoft Defender for Endpoint & Intune): Manage EDR policies, device compliance rules, Attack Surface Reduction (ASR) rules, and automated remediation on Windows/mobile devices.
  • Email & Collaboration (Defender for Office 365): Oversee Safe Links, Safe Attachments, anti-phishing, anti-spam policies, and quarantine triage.
  • Data Protection & Governance (Purview): Implement and monitor Data Loss Prevention (DLP) policies, Sensitivity Labels, and Information Barrier policies across M365 services.
  • Cloud Apps (Defender for Cloud Apps): Monitor shadow IT, manage OAuth app permissions, and enforce session policies.
  • 2. Microsoft Sentinel (SIEM/SOAR) Operations
    • Data Connector Management: Maintain and optimize log ingestion from M365, Entra ID, Defender XDR, firewalls, and cloud infrastructure while keeping ingestion costs efficient.
    • Detection & Analytics: Write and update KQL (Kusto Query Language) analytics rules, hunting queries, and custom workbooks/dashboards.
    • Automation (SOAR): Build and maintain Logic Apps playbooks to automate incident response workflows and threat containment.
    • Incident Response: Perform Tier 2/3 triage, investigation, and root-cause analysis on alerts originating from Defender XDR and Sentinel.
  • 3. Operational Support & Maintenance (~300 Users)
    • License & Tenant Health: Continuously review Microsoft Secure Score, address recommendations, and audit user license assignments.
    • Patch & Vulnerability Management: Monitor Defender Vulnerability Management insights and coordinate with IT support to remediate endpoint software vulnerabilities.
    • User Escalations: Handle escalated support tickets regarding access blocks, false positives, quarantine releases, or compromised account recovery.
    • Reporting & Documentation: Maintain accurate security operational runbooks, architecture diagrams, and monthly threat/compliance reporting for management.

Requirements

  • 3+ years of hands-on experience administering Microsoft 365 security features, specifically within an E5 / Defender XDR environment.
  • 3+ years of experience configuring and operating Microsoft Sentinel.
  • Strong proficiency in writing KQL (Kusto Query Language) queries for logs, investigations, and analytics rules.
  • Experience with Microsoft Intune (MDM/MAM) for Windows endpoint management.
  • Solid understanding of PowerShell for M365 scripting and security automation.
  • Hands-on knowledge of networking basics (DNS, Firewalls, VPNs) and cloud identity fundamentals (Entra ID, SAML, SSO).

 Desirable Certifications (At least one preferred)

  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) (Highly Desirable)
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)

Similar Jobs

See all Remote Others jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Others

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified