Security Engineer III
Core
Build serverless, event-driven security workflows and playbooks to automate email threat triage, remediation, and incident response using Microsoft Sentinel, Defender XDR, and AI-driven agents.
Role type
Senior IC security automation engineer (email security)
Builds
Automated security playbooks, AI-driven triage pipelines, and governance workflows for enterprise email environments
Domain
Cybersecurity, Email Security, Cloud Security (Microsoft 365)
Deliverable
production ML models | product features
Required skills
Serverless architecture, Event-driven workflows, Microsoft Graph Security API, REST/HTTP integration, No-code/Low-code workflow building, Agentic AI integration, Email header analysis, SMTP mechanics, DNS record management (MX, SPF, DKIM, DMARC), Exchange server management, Incident response methodologies, Threat intelligence platforms, Security auditing, Regulatory compliance (GDPR, HIPAA)
Preferred skills
Experience with Cisco ESA/SMA, Fortra Agari, RedSift, ServiceNow, Microsoft Power Automate
Technologies
Microsoft Sentinel, Microsoft Defender XDR, Microsoft Graph Security API, Microsoft Power Automate, Microsoft Defender for Cloud Apps, ServiceNow, Cisco ESA, Fortra Agari, RedSift
Responsibilities
Build serverless security workflows triggered by security incidents; Integrate with Microsoft Graph Security API for user isolation and message purging; Assemble complex triage pipelines using visual canvas builders; Connect alerts with third-party tools for file hash checks and URL reputation analysis; Construct human-in-the-loop approval workflows for destructive actions; Manage and maintain email security solutions and monitor email traffic for compliance
Seniority
Senior, hands-on IC