← The wire

Microsoft Security Engineer

King & Spalding · Atlanta, Georgia

Posted 15h ago · first seen by the radar 43m ago · last checked on the employer's board 13m ago

Onsite · Full time

King & Spalding is a leading global law firm with a commitment to excellence, innovation, and the seamless delivery of legal services. We harness innovative technology and exceptional talent to meet the complex needs of our clients in a fast-paced and dynamic legal landscape.

The Microsoft Security Engineer is responsible for designing, implementing, configuring, and maintaining enterprise security capabilities across the Microsoft security ecosystem. This role supports identity protection, endpoint security, cloud security, email security, data protection, threat detection, and security operations by using Microsoft technologies such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, and related Microsoft 365 security services.

KEY RESPONSIBILITIES:

  • Administer, configure, and optimize Microsoft security platforms, including Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and related security services.
  • Design and implement security policies, standards, controls, and configurations that reduce risk and improve the organization’s overall security posture.
  • Manage identity and access security controls, including creating conditional access policies.
  • Support endpoint, email, identity, cloud application, and data protection security operations through effective security policies.
  • Develop and maintain detection logic, alert rules, automation, playbooks, dashboards, and operational procedures within Microsoft Sentinel and Microsoft Defender.
  • Partner with threat response, detection engineering, infrastructure, endpoint, messaging, and compliance teams to improve prevention, detection, response, and recovery capabilities.
  • Perform security health checks, configuration reviews, control validation, and hardening activities across Microsoft 365, Azure, endpoint, identity, email, and SaaS environments.
  • Support investigations associated with phishing, malware, account compromise, suspicious authentication, data exposure, endpoint threats, and cloud-based threats.
  • Analyze logs, alerts, telemetry, indicators of compromise, and threat intelligence to identify suspicious behavior and partner with detection engineering teams create proactive alerts.
  • Stay current on Microsoft security capabilities, emerging cyber threats, industry best practices, and regulatory or compliance requirements affecting enterprise security operations.
  • Participate in change management, security projects, audit support, vulnerability remediation, and after-hours incident response or on-call coverage as required.

QUALIFICATIONS:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent professional experience may be considered in lieu of a degree.
  • Minimum of 3–5 years of experience in information security, security engineering, security operations, cloud security, identity security, endpoint security, or a related IT security role.
  • Hands-on experience administering or supporting Microsoft security technologies, such as Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, Microsoft 365 security, or Azure security services.
  • Strong understanding of cybersecurity principles, including defense-in-depth, least privilege, identity and access management, endpoint protection, email security, cloud security, vulnerability management, logging, monitoring, and incident response.
  • Experience configuring and maintaining security policies, conditional access rules, authentication controls, endpoint security baselines, data protection policies, and alerting rules.
  • Ability to investigate security alerts, analyze logs and telemetry, identify root cause, document findings, and recommend remediation actions.
  • Working knowledge of enterprise infrastructure, including Windows, Active Directory, Azure, Microsoft 365, networking fundamentals, DNS, email flow, authentication protocols, and cloud services.
  • Experience using scripting, query, or automation tools such as PowerShell, Kusto Query Language (KQL), Microsoft Graph, Logic Apps, or similar technologies.
  • Ability to communicate technical concepts clearly to security teams, IT stakeholders, business partners, leadership, and non-technical audiences.
  • Strong analytical, troubleshooting, documentation, collaboration, and time-management skills.
  • Ability to work independently and as part of a cross-functional team in a fast-paced enterprise environment.
  • Willingness to participate in incident response, maintenance windows, and on-call rotations when required.

DESIRED QUALIFICATIONS:

  • Microsoft security certifications such as SC-200, SC-300, SC-400, AZ-500, MS-102, or equivalent cloud/security certifications.
  • Experience with Microsoft Defender XDR incident queues, Advanced Hunting, secure score improvement, attack simulation, endpoint detection and response, email protection, identity protection, or cloud app security.
  • Experience building, tuning, or maintaining SIEM use cases, analytics rules, workbooks, dashboards, automation, and incident response playbooks within Microsoft Sentinel.
  • Experience supporting Microsoft Purview Data Loss Prevention, information protection, sensitivity labels, retention policies, insider risk, eDiscovery, or compliance-related security controls.
  • Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, MITRE ATT&CK, ISO 27001, or similar industry guidance.
  • Experience with threat hunting, detection engineering, malware analysis, phishing investigation, business email compromise response, or account compromise investigation.
  • Experience with cloud platforms, SaaS security, CASB capabilities, Azure security, Google Cloud Platform security, or multi-cloud security operations.
  • Experience working with ticketing systems, change management processes, vulnerability management platforms, and enterprise incident response workflows.
  • Strong written communication skills with the ability to produce clear technical documentation, investigation summaries, executive-level updates, and operational procedures.
  • Demonstrated commitment to continuous learning, process improvement, operational excellence, and maintaining awareness of evolving Microsoft security features and cyber threats.

The firm offers a generous total compensation package with bonuses and raises awarded in recognition of individual merit-based performance. All full-time Business Services employees may participate in King & Spalding’s comprehensive benefit program including health and wellness plan, life and disability insurance, flexible spending accounts and a health savings account, a 401(k) plan, profit sharing plan, and a substantial Paid Time Off (PTO) program.

King & Spalding LLP (K&S) is committed to providing equal employment opportunity to all applicants and employees in full compliance with all state, federal, and local laws prohibiting discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, age, disability or any other status protected by applicable law. 

We are proud of our remarkably cohesive culture, which now encompasses more than 2,500 lawyers and business professionals worldwide. We seek to attract and develop the very best talent to work with us.

Listing read directly from King & Spalding's applicant tracking system. Check frequency varies by source. Listings are removed after successful checks confirm they are no longer present.