Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Senior Microsoft Security Administrator

Al-Watania Information Systems
CompanyAl-Watania Information Systems
CategoryUncategorised
LocationRiyadh
RemoteOn-site (inferred)
EmploymentFull-time
LevelNot stated
SalaryNot stated by the employer
Posted2 Aug 2026
Last verified3 Aug 2026
SourceEmployer ATS (workable)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
1. M365 E5 Security Administration & Engineering Identity & Access (Entra ID): Configure and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection rules. Endpoint Security (Microsoft Defender for Endpoint & Intune): Manage EDR policies, device compliance rules, Attack Surface Reduction (ASR) rules, and automated remediation on Windows/mobile devices. Email & Collaboration (Defender for Office 365): Oversee Safe Links, Safe Attachments, anti-phishing, anti-spam policies, and quarantine triage. Data Protection & Governance (Purview): Implement and monitor Data Loss Prevention (DLP) policies, Sensitivity Labels, and Information Barrier policies across M365 services. Cloud Apps (Defender for Cloud Apps): Monitor shadow IT, manage OAuth app permissions, and enforce session policies. 2. Microsoft Sentinel (SIEM/SOAR) Operations Data Connector Management: Maintain and optimize log ingestion from M365, Entra ID, Defender XDR, firewalls, and cloud infrastructure while keeping ingestion costs efficient. Detection & Analytics: Write and update KQL (Kusto Query Language) analytics rules, hunting queries, and custom workbooks/dashboards. Automation (SOAR): Build and maintain Logic Apps playbooks to automate incident response workflows and threat containment. Incident Response: Perform Tier 2/3 triage, investigation, and root-cause analysis on alerts originating from Defender XDR and Sentinel. 3. Operational Support & Maintenance (~300 Users) License & Tenant Health: Continuously review Microsoft Secure Score, address recommendations, and audit user license assignments. Patch & Vulnerability Management: Monitor Defender Vulnerability Management insights and coordinate with IT support to remediate endpoint software vulnerabilities. User Escalations: Handle escalated support tickets regarding access blocks, false positives, quarantine releases, or compromised account recovery. Reporting & Documentation: Maintain accurate security operational runbooks, architecture diagrams, and monthly threat/compliance reporting for management.