Cybersecurity Engineer – Microsoft Security Defender Entra ID & Purview

Square One Resources Remote Warszawa 2026-10-08
Requirements
Must-have
  • 3+ years of professional experience in Cybersecurity, Security Engineering, or Security Operations.
  • Strong and practical knowledge of the Microsoft security ecosystem.
  • Advanced knowledge of Microsoft Defender, including:
    • Microsoft Defender XDR
    • Microsoft Defender for Endpoint
    • Microsoft Defender for Cloud
  • Advanced knowledge of Microsoft Entra ID (Azure AD).
  • Advanced knowledge of Microsoft Purview, including Data Loss Prevention (DLP) capabilities.
  • Practical experience with Microsoft Sentinel and SIEM-based security monitoring.
  • Strong understanding of Endpoint Security and modern antivirus/EDR solutions.
  • Good understanding of Identity and Access Management (IAM).
  • Knowledge of Zero Trust security principles.
  • Experience with Security Monitoring and Incident Response.
  • Understanding of Vulnerability Management processes and tools.
  • Knowledge of Cloud Security, preferably within Microsoft Azure.
  • Ability to investigate security incidents and analyze security events.
  • Ability to work effectively in international, English-speaking, cross-functional teams.
Nice-to-have
  • Experience with PowerShell and/or Python for security scripting and automation.
  • Knowledge of security frameworks and standards such as:
    • NIST
    • ISO 27001
    • CIS Controls
  • Microsoft security certifications, particularly:
    • SC-100 – Microsoft Cybersecurity Architect
    • SC-200 – Microsoft Security Operations Analyst
    • SC-300 – Microsoft Identity and Access Administrator
  • Experience supporting large-scale cloud and security transformation projects.
  • Experience with security automation and development of automated response mechanisms.
Technology Stack
  • Microsoft Defender XDR – Advanced
  • Microsoft Defender for Endpoint – Advanced
  • Microsoft Defender for Cloud – Advanced
  • Microsoft Entra ID – Advanced
  • Microsoft Purview – Advanced
  • Microsoft Sentinel – Advanced
  • Microsoft Azure – Regular
  • PowerShell / Python – Nice to have
  • SIEM solutions
  • Vulnerability Management tools
Project Description
We are looking for a Mid-level Cybersecurity Engineer to join an international security engineering environment focused on the development, administration, and continuous improvement of Microsoft-based security solutions across cloud and on-premises environments.
The project covers a broad range of cybersecurity areas, including security monitoring, threat detection, incident response, vulnerability management, identity and access management, endpoint security, cloud security, and security automation.
The role will be particularly focused on advanced security capabilities within the Microsoft ecosystem, including Microsoft Defender, Microsoft Entra ID, Microsoft Purview, and Microsoft Sentinel.
You will work in international, cross-functional teams and contribute to large-scale cloud and cybersecurity transformation initiatives.
Recruitment Process
The recruitment process consists of three stages:
  1. Initial interview – approximately 60 minutes, online via MS Teams.
  2. Technical interview – approximately 60 minutes, including technical knowledge verification.
  3. Team interview + technical assessment – approximately 60 minutes, with the future team and additional technical verification.
,[Design, implement, configure, and continuously improve Microsoft security solutions across cloud and on-premises environments., Manage and develop Microsoft Defender XDR, Defender for Endpoint, and Defender for Cloud capabilities., Develop and maintain security monitoring and detection capabilities using Microsoft Sentinel and SIEM solutions., Create, tune, and optimize detection rules, alerts, and security policies., Monitor security events, investigate suspicious activities, and support incident detection and response., Participate in incident response activities, including investigation, containment, and remediation., Support security investigations and forensic analysis when required., Develop and maintain Data Loss Prevention (DLP) policies and controls, particularly within Microsoft Purview., Configure and optimize Microsoft Purview security and compliance capabilities., Support Endpoint Security and advanced antivirus/EDR protection, including Microsoft Defender for Endpoint., Work with Microsoft Entra ID to support Identity and Access Management, authentication, authorization, and access controls., Contribute to the implementation of Zero Trust security principles., Support vulnerability management activities, including vulnerability identification, assessment, prioritization, and remediation., Contribute to Cloud Security initiatives within Microsoft Azure environments., Develop scripts and automation using PowerShell and/or Python where applicable., Collaborate with security, infrastructure, cloud, and application teams in an international environment., Contribute to the continuous improvement of security processes, standards, and technical controls., Support large-scale cloud and cybersecurity transformation projects.] Requirements: Cybersecurity, Security, Cloud, Azure AD, Data Loss Prevention, DLP, Antivirus, EDR, IAM, Cloud security, Microsoft Azure, PowerShell, Python, NIST, ISO, CIS, SIEM