Senior Microsoft Security Administrator
Job in
Riyadh, Riyadh Region, Saudi Arabia
Listed on 2026-08-05
Listing for:
Al Watania Information Systems (Wisys)
Full Time
position Listed on 2026-08-05
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations, Systems Administrator
Job Description & How to Apply Below
- M365 E5 Security Administration & Engineering
- Identity & Access (Entra ):
Configure and maintain Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Identity Protection rules - Endpoint Security (Microsoft Defender for Endpoint & Intune):
Manage EDR policies, device compliance rules, Attack Surface Reduction (ASR) rules, and automated remediation on Windows/mobile devices - Email & Collaboration (Defender for Office
5):
Oversee Safe Links, Safe Attachments, anti-phishing, anti-spam policies, and quarantine triage - Data Protection & Governance (Purview):
Implement and monitor Data Loss Prevention (DLP) policies, Sensitivity Labels, and Information Barrier policies across M365 services - Cloud Apps (Defender for Cloud Apps):
Monitor shadow IT, manage OAuth app permissions, and enforce session policies. - 2. Microsoft Sentinel (SIEM/SOAR) Operations
- Data Connector Management:
Maintain and optimize log ingestion from M365, Entra , Defender XDR, firewalls, and cloud infrastructure while keeping ingestion costs efficient - Detection & Analytics:
Write and update KQL (Kusto Query Language) analytics rules, hunting queries, and custom workbooks/dashboards - Automation (SOAR):
Build and maintain Logic Apps playbooks to automate incident response workflows and threat containment - Incident Response:
Perform Tier 2/3 triage, investigation, and root-cause analysis on alerts originating from Defender XDR and Sentinel
- Data Connector Management:
- 3. Operational Support & Maintenance (:300 Users)
- License & Tenant Health:
Continuously review Microsoft Secure Score, address recommendations, and audit user license assignments - Patch & Vulnerability Management:
Monitor Defender Vulnerability Management insights and coordinate with IT support to remediate endpoint software vulnerabilities - User Escalations:
Handle escalated support tickets regarding access blocks, false positives, quarantine releases, or compromised account recovery - Reporting & Documentation:
Maintain accurate security operational runbooks, architecture diagrams, and monthly threat/compliance reporting for management
- License & Tenant Health:
- 3+ years of hands‑on experience administering Microsoft 365 security features, specifically within an E5 / Defender XDR environment
- 3+ years of experience configuring and operating Microsoft Sentinel
- Strong proficiency in writing KQL (Kusto Query Language) queries for logs, investigations, analytics rules
- Experience with Microsoft Intune (MDM/MAM) for Windows endpoint management
- Solid understanding of Power Shell for M365 scripting and security automation
- Hands‑on knowledge of networking basics (DNS, Firewalls, VPNs) and cloud identity fundamentals (Entra , SAML, SSO)
- Microsoft Certified:
Identity and Access Administrator Associate (SC-300) - Microsoft Certified:
Information Protection and Governance Administrator Associate (SC-400) - Microsoft Certified:
Security Operations Analyst Associate (SC-200) (Highly Desirable) - Microsoft Certified:
Cybersecurity Architect Expert (SC-100)
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×