Live opening · Posted 2 days ago

Microsoft Security Operations

SourceFuse · Noida, Uttar Pradesh, India (On-site)
Linkedin No
You are 2 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 2 days ago
CompanySourceFuse
LocationNoida, Uttar Pradesh, India (On-site)
Work modeNo
SourceLinkedin
Listed2 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
13 min from Linkedin publishing this role to us finding it
9 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
17,073 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

SourceFuse is an AWS Premier Tier Services Partner with eight competencies, ISO 27001:2022, SOC 2, ISO 9001:2015 and HIPAA certification. Our managed services practice runs cloud, data and GenAI workloads for clients in healthcare, financial services and life sciences.
We are now opening a Microsoft security operations line. The first engagement is a 24/7 white-labelled managed SOC for a UK client on a Microsoft 365 centric estate, up to 500 nodes, delivered as Sentinel-based MXDR.
You build that service, then hand it to our managed services team to run. After that, you are the person who grows this capability across the rest of our client base. This is a practice investment, not a single-project contract.
Experience Level - 8+ Years
Preferred Location - Mohali/Noida, India
Shift - UK Overlap
What you will do
● Run discovery and gap analysis workshops with clients. Scope the estate, size the node count, agree log sources, and produce the assessment that the commercial quote rests on.
● Design and stand up Microsoft Sentinel end to end: data connectors, data collection rules, analytics rules, watchlists, UEBA, workbooks, Logic App playbooks, and ingestion cost tuning.
● Deploy and tune Defender for Endpoint. Configure Defender for Office 365, Identity and Cloud Apps.
● Build detection content mapped to MITRE ATT&CK, and write the triage, escalation and containment runbooks behind it.
● Stand up 24/7 operations with our L1 and L2 team: shift handover, SLA definitions, escalation paths and DFIR handoff.
● Produce audit-grade monitoring and detection evidence for client compliance frameworks. Our clients use this output as certification evidence, so it has to survive an auditor.
● Deliver multi-tenant and white-labelled services through Microsoft Lighthouse, where the end client never sees us.
● Evaluate and quote third party MDR platforms such as SentinelOne where the native Microsoft stack is not the right fit.
● Train and certify the existing managed services team. Knowledge transfer is a deliverable of this role, not a courtesy.
● Support presales: scoping calls, effort and cost models, and technical responses to tenders.
What you need to have done before
● Stood up at least one greenfield Sentinel tenant end to end, and can walk us through the decisions you made and the ones you would change.
● KQL fluency. We will assess this live.
● Defender for Endpoint deployment, policy and tuning at scale.
● Incident response in practice, from triage through containment to DFIR handoff.
● Multi-tenant or white-label delivery inside an MSSP or managed service.
● SC-200 certification.
● Enough client presence to run a discovery workshop with a client leadership team on your own.
● A track record of documenting what you built and training other people to run it.
Useful on top
● Evidence packs for UK frameworks: Cyber Essentials, DCC, NIST CSF or ISO 27001.
● Azure platform security: landing zones, Azure Policy, Entra ID, Key Vault.
● Automation with Logic Apps, PowerShell, Bicep or Terraform.
● AWS security exposure such as GuardDuty and Security Hub. We are an AWS-first house and the two practices will sit side by side.
Who this role is not for
● A tier one SOC analyst. We already have monitoring capacity. The gap is the engineering above it.
● A GRC or audit consultant. That ground is already covered internally.
● An Azure infrastructure architect who has not done detection engineering.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App