Security Automation and Incident Response Engineer
Straight from Magnet Forensics’s careers page. Apply on the company site — no recruiter, no middleman.
Microsoft Security Automation & Incident Response Engineer - Contract Position
Team: Security
Location: United States
Commitment: Contract
Workplace Type: remote
Magnet Forensics is seeking a highly skilled Microsoft Security Automation & Incident Response Engineer to accelerate the maturity and efficiency of our security operations program.
This resource will be responsible for optimizing and integrating Microsofts security platform, reducing manual analyst workload, automating repetitive tasks, improving detection coverage, and enhancing incident response capabilities.
The ideal candidate is a hands-on engineer with deep experience in Microsoft Sentinel, Defender XDR, automation, and modern security operations.
This is a 3-4 month contract role
What Youll Do
- Analyze existing alert triage and incident response processes
- Identify operational bottlenecks and manual activities
- Implement improvements that reduce analyst effort and response times
- Improve overall SOC efficiency and effectiveness
- Tune Microsoft Sentinel analytics rules
- Reduce false positives and alert fatigue
- Create advanced correlation rules and hunting content
- Improve quality and fidelity of security detections
- Alert enrichment
- Incident routing
- Ticket creation
- Escalation workflows
- Investigation support
- Standard response actions
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud Apps
- Entra ID
- Zscaler telemetry
- Existing ITSM and ticketing platforms
- Improve incident response processes
- Enhance investigation playbooks
- Develop response automation
- Create operational runbooks and documentation
Security Operations Optimization
Detection Engineering
Security Automation
Design and implement automation for:
Platform Integration
Optimize and integrate:
Incident Response Support
What Were Looking For
- 5+ years in Security Operations, Detection Engineering, or Incident Response
- Strong Microsoft Sentinel experience
- Strong Microsoft Defender suite experience
- Advanced KQL skills
- Logic Apps experience
- SOAR automation experience
- SIEM engineering experience
- Security operations workflow optimization experience
- Microsoft Security certifications
- Threat hunting experience
- Detection engineering background
- Experience integrating third-party security telemetry
- Exposure to Purview and DLP technologies
Required Qualifications
Preferred Qualifications
Similar remote jobs
All Security Engineer jobs →
CoreWeave
Senior Security Engineer, eDiscovery, Insider Risk

Clarivate
Senior Director, Cyber Security


CrowdStrike
Platform Professional Services Analyst (Remote)
Discover More than 100,000 Hidden Remote Jobs Before Everyone Else
Unlock All Remote Jobs Today
Simple pricing. Big savings on Quarterly and Yearly.
Monthly Access
- Instant access to fresh remote jobs from 500+ companies
- New opportunities added hourly, often 3-7 days before anywhere else
- Advanced filtering by role type, stack, pay, and location
- Priority customer support
Yearly Access
- Everything in Monthly
- Save $169 (~74%) vs paying monthly
- Average job search takes ~6 months - get covered for the whole journey
- Less than the cost of one lunch per month for competitive advantage
- Equivalent to just ~$4.92/month