A
Senior Microsoft Security Administrator
Al Watania Information Systems (Wisys)
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- 3+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 hours ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Job description
Role Overview
We are seeking a Senior Microsoft Security Administrator to join our team in Riyadh. This position entails managing and engineering various Microsoft 365 security components, overseeing Microsoft Sentinel SIEM/SOAR operations, and providing operational support for approximately 300 users.
Key Responsibilities
- Administer Microsoft 365 E5 Security solutions, including Identity and Access management through Entra ID (Configuration of Conditional Access, MFA, PIM, Identity Protection).
- Manage endpoint security using Microsoft Defender for Endpoint and Intune, focusing on EDR policies, compliance enforcement, Attack Surface Reduction, and automated remediation for Windows and mobile devices.
- Supervise email and collaboration protection with Defender for Office 365 by handling Safe Links, Safe Attachments, anti-phishing, anti-spam policies, and quarantine review processes.
- Implement and monitor Data Loss Prevention (DLP), Sensitivity Labels, and Information Barrier policies via Microsoft Purview.
- Monitor cloud applications, control OAuth permissions, assess shadow IT, and enforce session controls using Defender for Cloud Apps.
- Operate Microsoft Sentinel for SIEM/SOAR tasks including data connector management from various sources, writing and updating KQL analytics queries and custom dashboards, creating Logic Apps playbooks for automated incident responses, and conducting Tier 2/3 alert triage and investigations.
- Provide ongoing operational maintenance such as managing licenses and tenant health through Microsoft Secure Score, patch and vulnerability assessments, addressing user escalations related to security issues, and maintaining security documentation and monthly reporting.
Candidate Requirements
- A minimum of 3 years administering Microsoft 365 security capabilities with experience in E5/Defender XDR environments.
- At least 3 years of hands-on experience operating Microsoft Sentinel.
- Strong expertise in Kusto Query Language (KQL) for log analysis, detection rule creation, and security analytics.
- Proficiency in Microsoft Intune for device management (MDM/MAM) on Windows platforms.
- Working knowledge of PowerShell for scripting and automating Microsoft 365 security tasks.
- A sound foundational understanding of networking concepts (such as DNS, firewall configurations, VPNs) and cloud identity protocols (Entra ID, SAML, SSO).
Preferred Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Information Protection and Governance Administrator Associate (SC-400)
- Microsoft Certified: Security Operations Analyst Associate (SC-200) – Highly Recommended
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Skills
Microsoft Intune
Incident Response
PowerShell Scripting
Data Loss Prevention (DLP)
Microsoft Sentinel
Endpoint detection and response (EDR)
Kusto Query Language (KQL)
Microsoft 365 Security Administration
Cloud Identity Management
Multi-Factor Authentication (MFA)
Conditional access policies
Firewall and VPN Fundamentals