Cybersecurity Engineer (Architecture, Infrastructure and Remediation)
LevelBlue LLC United States · $85K–$120K/yr
Computer and Network Security · 501-1,000 employees
About the role
The Senior Cybersecurity Engineering Consultant will lead Purview engagements, including current-state assessments, target design, and configuration of security controls. They will also implement and harden Microsoft Defender XDR and Entra ID security while producing client-ready artifacts and facilitating stakeholder workshops.
What they look for
Requirements
Candidates must have hands-on experience implementing Microsoft Purview, Defender XDR, and Entra ID in production environments. A background in professional services or senior consulting with a proven ability to design and configure security controls is required.
Full description
About LevelBlue
LevelBlue is a leading cybersecurity and managed security services provider focused on threat detection and response. Leveraging our Fusion platform, global threat intelligence, and deep expertise across offensive and defensive security disciplines, we help organizations across financial services, retail, healthcare, government, and utilities manage risk and respond to the threats that matter most.
Our Professional Services practice works alongside clients at every stage of their security maturity – from strategy and architecture through to hands-on delivery, operations uplift, and incident response. We are a team of practitioners who have built and run security programs ourselves, and we bring that credibility to every engagement.
LevelBlue’s Professional Services Organization is hiring a Senior Cybersecurity Engineering Consultant to implement and uplift Microsoft security for clients, especially Purview, and to take hands-on control work. You will own scoped delivery: requirements, target configuration, guided or hands-on implementation, and client-ready artifacts. You will run workshops, give SME-level guidance, and support recommendations with configuration evidence. You will work with autonomy and in mixed delivery and client teams, own your workstream, and improve practice proposals and delivery assets. This is not policy-only work or default-on exercise. You will have implemented Purview and adjacent Microsoft security controls in live tenants.
Role Expectations / Key Responsibilities
Engagement Deliver
• Lead Purview engagements: current-state assessment, target design, phased rollout, and configuration of scoped capabilities (information protection, DLP, audit, and related controls).
• Implement and harden Microsoft Defender XDR and Entra ID security (including Conditional Access and identity-protection patterns) for the client’s operating model, not a demo tenant.
• Deliver Azure security posture assessments and guided hardening: landing-zone and control-plane hygiene, Defender for Cloud, prioritized roadmap.
• Where scoped, deliver assessment-level Active Directory / hybrid identity work: privilege, delegation, legacy protocol exposure, and a prioritized hardening roadmap.
• Produce client-ready artifacts: gap analyses, configuration baselines, implementation plans, and operational handover that can be executed.
• Run workshops with security, compliance, identity, and IT stakeholders; capture requirements, decisions, risks, and scope changes.
• Support pre-sales with effort estimates, technical scope, and solution shaping.
Experience & Qualifications
Required
• Senior consulting or professional-services delivery: workshops, scope, and artifacts the client accepted.
• Hands-on Microsoft Purview implementation in a production or client tenant; you have designed and configured controls.
• Hands-on Microsoft Defender XDR (at least Defender for Endpoint plus one of Identity, Office, or Cloud Apps).
• Hands-on Entra ID security: Conditional Access, identity protection / risk patterns, and privileged-access basics as implemented in the tenant.
• Ability to assess requirements and recommend a target configuration with a practical how-to, including what to phase and what not to turn on.
Strongly Preferred
• Active Directory security assessments in hybrid estates (privilege, stale admin paths, legacy auth, hardening roadmap).
• Azure security assessments and control implementation, including Defender for Cloud.
• Landing Purview, Defender, and Entra telemetry in Microsoft Sentinel (connectors, data usefulness, detections).
Useful
• AWS or multi-cloud posture reviews.
• Network-edge reviews (firewall/VPN policy, logging, segmentation) on occasional engagements
Certifications (desirable)
• Most relevant: SC-400; SC-300; SC-200
• Also useful: SC-500 (AZ-500); SC-100; CISSP or CISM
Similar roles
-
Teamlead Data & Cybersecurity
Cosun Dinteloord, North Brabant, Netherlands · €56K–€74K/yr
-
Cybersecurity GRC Consultant - Categoria protetta L.68/99
BIP Consulting Palermo, Sicily, Italy · €28K–€34K/yr
-
OT Engineer Cybersecurity
Cosun Dinteloord, North Brabant, Netherlands · €54K–€71K/yr
-
Working Student, Security Engineer
GetYourGuide Zurich, Zurich, Switzerland
-
AI Cybersecurity Researcher
Check Point Software Technologies Tel-Aviv, Tel-Aviv District, Israel
-
Three SG - Apprentice Fire and Security Engineer
Apprenticeships at Skills for Security Castle Point, England, United Kingdom · £17K/yr