Senior Microsoft Security Administrator

AlWatania Information Systems

About The Position

This role focuses on administering and engineering Microsoft 365 security features, with a strong emphasis on M365 E5 Security, Microsoft Defender XDR, and Microsoft Sentinel. The position involves managing identity and access, endpoint security, email and collaboration security, data protection, and cloud app security within the M365 ecosystem. Additionally, it requires operational support for Microsoft Sentinel (SIEM/SOAR), including data connector management, detection and analytics using KQL, automation through Logic Apps, and incident response. The role also encompasses operational support and maintenance for approximately 300 users, including license and tenant health monitoring, patch and vulnerability management, handling user escalations, and maintaining documentation and reporting.

Requirements

  • 3+ years of hands-on experience administering Microsoft 365 security features, specifically within an E5 / Defender XDR environment.
  • 3+ years of experience configuring and operating Microsoft Sentinel.
  • Strong proficiency in writing KQL (Kusto Query Language) queries for logs, investigations, and analytics rules.
  • Experience with Microsoft Intune (MDM/MAM) for Windows endpoint management.
  • Solid understanding of PowerShell for M365 scripting and security automation.
  • Hands-on knowledge of networking basics (DNS, Firewalls, VPNs) and cloud identity fundamentals (Entra ID, SAML, SSO).

Nice To Haves

  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) (Highly Desirable)
  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)

Responsibilities

  • Configure and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection rules.
  • Manage EDR policies, device compliance rules, Attack Surface Reduction (ASR) rules, and automated remediation on Windows/mobile devices.
  • Oversee Safe Links, Safe Attachments, anti-phishing, anti-spam policies, and quarantine triage.
  • Implement and monitor Data Loss Prevention (DLP) policies, Sensitivity Labels, and Information Barrier policies across M365 services.
  • Monitor shadow IT, manage OAuth app permissions, and enforce session policies.
  • Maintain and optimize log ingestion from M365, Entra ID, Defender XDR, firewalls, and cloud infrastructure while keeping ingestion costs efficient.
  • Write and update KQL (Kusto Query Language) analytics rules, hunting queries, and custom workbooks/dashboards.
  • Build and maintain Logic Apps playbooks to automate incident response workflows and threat containment.
  • Perform Tier 2/3 triage, investigation, and root-cause analysis on alerts originating from Defender XDR and Sentinel.
  • Continuously review Microsoft Secure Score, address recommendations, and audit user license assignments.
  • Monitor Defender Vulnerability Management insights and coordinate with IT support to remediate endpoint software vulnerabilities.
  • Handle escalated support tickets regarding access blocks, false positives, quarantine releases, or compromised account recovery.
  • Maintain accurate security operational runbooks, architecture diagrams, and monthly threat/compliance reporting for management.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service