
Senior Security Administrator, Microsoft
Posted Aug 3

Posted Aug 3
This is a fully remote position, open to applicants in Saudi Arabia.
• Administration and Engineering of M365 E5 Security
• Identity & Access (Entra ID): Set up and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection regulations.
• Endpoint Security (Microsoft Defender for Endpoint & Intune): Oversee EDR policies, device compliance standards, Attack Surface Reduction (ASR) measures, and automated remediation for Windows and mobile devices.
• Email & Collaboration (Defender for Office 365): Manage Safe Links, Safe Attachments, anti-phishing, anti-spam protocols, and quarantine triage processes.
• Data Protection & Governance (Purview): Establish and monitor Data Loss Prevention (DLP) policies, Sensitivity Labels, and Information Barrier policies across M365 services.
• Cloud Apps (Defender for Cloud Apps): Oversee shadow IT, manage OAuth app permissions, and enforce session policies.
• Operations for Microsoft Sentinel (SIEM/SOAR)
• Data Connector Management: Ensure efficient log ingestion from M365, Entra ID, Defender XDR, firewalls, and cloud infrastructure while keeping costs in check.
• Detection & Analytics: Craft and update KQL (Kusto Query Language) analytics rules, hunting queries, and custom workbooks/dashboards.
• Automation (SOAR): Develop and maintain Logic Apps playbooks for automating incident response workflows and threat containment.
• Incident Response: Conduct Tier 2/3 triage, investigation, and root-cause analysis on alerts from Defender XDR and Sentinel.
• Operational Support & Maintenance for approximately 300 Users
• License & Tenant Health: Regularly assess Microsoft Secure Score, implement recommendations, and audit user license assignments.
• Patch & Vulnerability Management: Keep track of Defender Vulnerability Management insights and collaborate with IT support to resolve endpoint software vulnerabilities.
• User Escalations: Manage escalated support tickets related to access blocks, false positives, quarantine releases, or recovery of compromised accounts.
• Reporting & Documentation: Maintain precise security operational runbooks, architecture diagrams, and monthly threat/compliance reports for management.
• A minimum of 3 years of practical experience with Microsoft 365 security features, particularly in an E5 / Defender XDR environment.
• At least 3 years of experience in configuring and operating Microsoft Sentinel.
• Strong expertise in writing KQL (Kusto Query Language) queries for logs, investigations, and analytics rules.
• Experience with Microsoft Intune (MDM/MAM) for managing Windows endpoints.
• A solid understanding of PowerShell for M365 scripting and security automation.
• Practical knowledge of networking fundamentals (DNS, Firewalls, VPNs) and cloud identity basics (Entra ID, SAML, SSO).
• Preferred Certifications (At least one is desirable)
• Microsoft Certified: Identity and Access Administrator Associate (SC-300)
• Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400)
• Microsoft Certified: Security Operations Analyst Associate (SC-200) (Highly Desirable)
• Microsoft Certified: Cybersecurity Architect Expert (SC-100)
• Competitive salary and performance-based bonuses
• Comprehensive health and wellness benefits
• Opportunities for professional development and growth
• Flexible work hours and remote work options
• Collaborative and inclusive work environment
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.