Seattle, WA

Salary
$120,000–$160,000from the description
Posted
Jun 29, 2026
Location
Seattle, WA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A hands-on security engineering role focused on managing and improving security controls within a Microsoft 365 and Azure environment, alongside on-premises systems. Core day-to-day work covers administering the Microsoft Defender suite and a CyberArk Privileged Access Management platform, building detection content and automated response playbooks, supporting incident response, and embedding security practices into infrastructure and development workflows. Suits an experienced security engineer comfortable with both platform operations and scripting-driven automation.

Senior level · 5+ years · Seattle-Tacoma-Bellevue, WA · Full-time

Must have (10)
Microsoft 365AzureCyberArkMicrosoft Sentinel, Splunk or Ibm QradarEntra IDPowerShell or PythonCI/CDNISTCISISO 27001

“or” means any one of them counts — you don't need all of them.

Posted 3 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 140 people in the Seattle-Tacoma-Bellevue, WA area plausibly meet what this posting asks for (information security analysts). range 75–220

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
PowerShell51%Python51%Entra ID50%Microsoft Sentinel45%CI/CD45%NIST40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $165,338 (middle half $132,613–$190,632). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The role title is 'Cybersecurity Engineer' with no level modifier, so advertised seniority is Unspecified; the 5+ years requirement and scope of ownership support a Senior classification.

SOC classification is a genuine judgment call: the role blends hands-on security engineering (automation, integrations, detection engineering — closer to 15-1252) with security operations and analysis (incident response, vulnerability management, SIEM — closer to 15-1212). The primary framing is security platform ownership and operations, so 15-1212 is the primary pick with 15-1252 as the runner-up.

The degree requirement states 'Bachelor's degree … or equivalent practical experience,' so no hard degree gate is set.

Certifications (SC-200, SC-300, SC-100, AZ-500, CISSP, CISM, GIAC) are listed as 'preferred' and are not emitted as skills.

PowerShell and Python are listed together as 'PowerShell and/or Python' — emitted as two separate skills each with the other as an alternative, reflecting that either satisfies the requirement.

Microsoft Sentinel is listed as an example ('e.g., Microsoft Sentinel or equivalent'); well-known SIEM alternatives are captured in the alternatives field.

NIST, CIS, and ISO 27001 are listed under the required Skills section as security frameworks candidates must be familiar with.

This is a hybrid role requiring at least 3 days/week in the Seattle office; it is not fully remote.

Ignored 4 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗