Senior Microsoft Security Administrator
Al-Watania Information Systems
| Company | Al-Watania Information Systems |
| Category | Uncategorised |
| Location | Riyadh |
| Remote | On-site (inferred) |
| Employment | Full-time |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 2 Aug 2026 |
| Last verified | 3 Aug 2026 |
| Source | Employer ATS (workable) |
Description
1. M365 E5 Security Administration & Engineering Identity & Access (Entra ID): Configure and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection rules. Endpoint Security (Microsoft Defender for Endpoint & Intune): Manage EDR policies, device compliance rules, Attack Surface Reduction (ASR) rules, and automated remediation on Windows/mobile devices. Email & Collaboration (Defender for Office 365): Oversee Safe Links, Safe Attachments, anti-phishing, anti-spam policies, and quarantine triage. Data Protection & Governance (Purview): Implement and monitor Data Loss Prevention (DLP) policies, Sensitivity Labels, and Information Barrier policies across M365 services. Cloud Apps (Defender for Cloud Apps): Monitor shadow IT, manage OAuth app permissions, and enforce session policies. 2. Microsoft Sentinel (SIEM/SOAR) Operations Data Connector Management: Maintain and optimize log ingestion from M365, Entra ID, Defender XDR, firewalls, and cloud infrastructure while keeping ingestion costs efficient. Detection & Analytics: Write and update KQL (Kusto Query Language) analytics rules, hunting queries, and custom workbooks/dashboards. Automation (SOAR): Build and maintain Logic Apps playbooks to automate incident response workflows and threat containment. Incident Response: Perform Tier 2/3 triage, investigation, and root-cause analysis on alerts originating from Defender XDR and Sentinel. 3. Operational Support & Maintenance (~300 Users) License & Tenant Health: Continuously review Microsoft Secure Score, address recommendations, and audit user license assignments. Patch & Vulnerability Management: Monitor Defender Vulnerability Management insights and coordinate with IT support to remediate endpoint software vulnerabilities. User Escalations: Handle escalated support tickets regarding access blocks, false positives, quarantine releases, or compromised account recovery. Reporting & Documentation: Maintain accurate security operational runbooks, architecture diagrams, and monthly threat/compliance reporting for management.