Full-Time

Cyber Defense & Resilience Senior Consultant

Microsoft Sentinel, Edr

Posted on 8/7/2025

Deloitte

Deloitte

10,001+ employees

Global professional services and auditing

Compensation Overview

$102.5k - $188.9k/yr

+ Discretionary Annual Incentive Program

Austin, TX, USA

In Person

Category
IT & Security (1)
Required Skills
Microsoft Azure
Python
AWS
Terraform
Google Cloud Platform
Requirements
  • 4+ years of experience in technical consulting, client problem solving, architecting, and designing solutions around Microsoft Sentinel, EDR & XDR platforms
  • 4+ years of hands-on technical experience enterprise-with Microsoft Security management services (Security information and event management (SIEM), IDS/IPS, Data Loss Prevention (DLP), Proxy, Web Application Firewall (WAF), Endpoint detection and response (EDR), Anti-Virus, Sandboxing, network and host-based firewalls, Threat Intelligence, Vulnerability Assessment, Penetration Testing, etc.)
  • 3+ years of hands-on technical experience implementing Microsoft Sentinel, EDR, XDR focused security solutions for Microsoft technologies
  • Limited immigration sponsorship may be available
  • Must be willing to travel 50%
Responsibilities
  • Experience in architecting, designing, and implementing the deployment of Cloud Services (Azure, AWS, GCP), Microsoft Sentinel, Defender for Endpoint/EDR, and XDR solutions to enhance clients' security posture.
  • Experience in forming KQL queries and functions for complex detection and monitoring requirements.
  • Expertise in building custom analytical rules, tuning of analytical rules, building automation through Azure logic apps, management of entire product feature, end to end configuration.
  • Ability to create clear and concise reports on security data and threats, including data visualization techniques.
  • Must have strong knowledge in MITRE attack framework and expertise in developing analytical rules and custom dashboards/workbooks across framework.
  • Assisting clients with migrating from existing SIEM solution (other platforms) to Microsoft Sentinel.
  • Expertise in log management, retentions, maintenance of logs at low cost, performing access management, developing new custom dashboard based on different requirements.
  • Must have proven record of implementing Sentinel advanced features, efficient log collection mechanisms, deployment and maintenance of log forwarders, and maintenance of local agents.
  • Expertise in integrating data sources which are not supported by Sentinel tool OOB. Custom parser development and ability to solve technical issues in Sentinel must have requirements. Experience with third-party data brokering service is a plus.
  • Experience with threat intelligence integration and UEBA (User and Entity Behavior Analytics).
  • Experience with scripting and automation tools (e.g., PowerShell, Python, Terraform) for security operations.
  • Provide end-to-end event analysis, incident detection, and manage escalations using documented procedures.
  • Develop, implement and refine automation playbooks in Microsoft Sentinel.
  • Devise and document new procedures and runbooks/playbooks as directed.
  • Create cyber and threat hunting queries to enable the Intelligence team to conduct advanced investigations when required.
  • Continuously improve the service by identifying and correcting issues or gaps in knowledge (analysis procedures, plays, client network models), false positive tuning, identifying and recommending new or updated tools, content, countermeasures, scripts, plug-ins, etc.
  • Experience in leveraging Security Copilot, creating custom prompts and integrating with threat sources.
  • Experience in connecting native and third-party custom/SaaS applications with SIEM.
  • Understanding of basic networking protocols such as TCP/IP, DNS, HTTP.
  • Understanding of possible attack activities such as network probing/scanning, DDOS, malicious code activity, etc.
  • Knowledge of Advanced Persistent Threats (APT) tactics, technics and procedures.
  • Acting as a subject matter expert on cyber risk for the Microsoft Sentinel, EDR & XDR platforms.
Desired Qualifications
  • BA/BS Degree preferred. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.
  • Certifications such as: Microsoft new roles-based certifications (eg. SC 200), CCSP, CCSK, CISSP, CCNP, CCNA certification a plus

What Deloitte does: Deloitte provides professional services to organizations, offering a range of services including consulting, auditing, tax, and advisory work to help clients improve performance and manage risk. How its products work: It blends practical advice with hands-on implementation through a global network of member firms and specialists. Teams assess clients’ needs, develop strategies, and help execute processes, controls, and transformations while upholding professional standards and integrity. How it differs from competitors: It operates at a large scale with a global network of diverse professionals, bringing cross‑disciplinary expertise and a wide range of services to many industries, which allows it to address complex challenges from multiple angles. What its goal is: To help clients and society become stronger by enabling sustainable progress and responsible growth through trusted services and collaboration.

Company Size

10,001+

Company Stage

Late Stage VC

Total Funding

$17.1M

Headquarters

Madrid, Spain

Founded

1845

Simplify Jobs

Simplify's Take

What believers are saying

  • U.S. revenues hit $35.7 billion in FY ended May 31, 2025.
  • Global network enables comprehensive delivery to multinational clients.
  • Strategic alliances advise clients across industries on initiatives.

What critics are saying

  • Fragmented firms isolate liability, damaging brand from misconduct.
  • EY, KPMG undercut AI audit prices, capturing 15-20% Global 500 contracts.
  • Talent exits to Palantir, Accenture halve consulting growth under Anna Marks.

What makes Deloitte unique

  • Deloitte's 470,000 global workforce spans 150 countries for multinational service.
  • Blends business acumen, technology, and alliances for industry future-building.
  • $70.5 billion FY2025 revenue reflects 4.8% growth in local currency.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Hybrid Work Options

Company News

Business Insider
Jan 29th, 2026
AI forces companies to rethink hiring practices as job applications surge and entry-level pipelines shrink

Business Insider convened 15 HR and C-suite leaders in Davos to discuss how AI is reshaping hiring and talent pipelines. The roundtable, presented by Indeed, revealed growing concerns about entry-level positions and skills assessment. Deloitte's Elizabeth Faber emphasised maintaining a "human-led, technology-powered" approach whilst carefully navigating reduced junior hiring. TCW's Melissa Stolfi noted her firm has downsized its analyst class but maintains a pyramid structure to preserve apprenticeship culture and future leadership pipelines. Indeed's chief economist Svenja Gudell warned that whilst tech employers now demand five-plus years' experience, this creates future talent shortages if junior hiring continues declining. Salesforce's Nathalie Scardino said her company receives two million applications annually and has shifted focus from years of experience to learning aptitude. Manpower Group's Becky Frankiewicz noted AI can process candidates faster whilst reducing bias, potentially unlocking opportunities beyond traditional qualifications.

Yahoo Finance
Jan 20th, 2026
Deloitte to hire 50,000 employees in India, eyes Mangaluru expansion

Deloitte plans to hire 50,000 employees in India and is evaluating Mangaluru, Karnataka, as a potential new location, according to South Asia CEO Romal Shetty. The company currently employs 140,000 people in India, representing one in four Deloitte employees globally. Shetty said India hosts 50% of all global capability centres worldwide, with significant growth potential in Tier II and Tier III cities. He proposed creating digital economic zones integrating GCCs, GPU-based data centres, startups and academic institutions to accelerate expansion. The CEO called for streamlining GCC setup processes from six months to two weeks, whilst acknowledging infrastructure constraints around energy and water for data centres. Shetty noted Mangaluru offers advantages including talent availability and real estate, adding the company's presence there is a matter of timing.

PR Newswire
Oct 31st, 2025
Deloitte Invests in Kihomac for Drones

Deloitte has invested in Kihomac to enhance U.S. drone manufacturing, aiming to strengthen national security and supply chains. This investment will allow Kihomac, a veteran-owned company, to expand production in Utah and mass-produce drones for U.S. government agencies and businesses. Deloitte's support will create manufacturing jobs and secure the supply chain for American customers.

La Tercera
Jul 14th, 2025
Deloitte Acquires Virtus Partners in Chile

Deloitte has acquired 100% of Virtus Partners, founded by Gonzalo and Marcelo Larraguibel, to enhance its strategic consulting business in Chile. This acquisition aims to offer comprehensive solutions from strategy design to execution. Deloitte's CEO, Christian Durán, emphasized the significance of this move in strengthening their market position. The merger combines Deloitte's global capabilities with Virtus Partners' local expertise, offering a unique strategic consulting platform in Chile.

Yahoo Finance
Jul 4th, 2025
Deloitte Canada Acquires Fintech Firm Allevar

Deloitte Canada has acquired Toronto-based fintech firm Allevar, enhancing its capabilities in regulatory compliance and technology solutions. Allevar specializes in fraud management, AML, payment systems, and KYC regulations, crucial for Canadian banks and the financial services industry. Allevar's leadership, including CEO Dan Wood, will join Deloitte's Regulatory Risk practice. This acquisition aligns with Deloitte's strategy for growth in the digital and AI age.

INACTIVE