- Own detection coverage across Defender XDR, Entra ID, Sentinel, Microsoft Graph, Azure, and Microsoft 365.
- Build and maintain a living map of Microsoft security signal including ingestion lags, data storage, and schema reliability.
- Track signal changes and proactively address drift to maintain detection efficacy.
- Automate Microsoft-specific investigative workflows against Graph, Defender, Sentinel, and Entra APIs.
- Partner with Engineering on Microsoft integration architecture, API management, and schema mapping.
- Answer technical inquiries from SOC, CS, and Sales teams and provide mentorship.
- Advise customers on their current security coverage, gaps, and potential improvements.