Back to jobs

Security Innovation Intern (SC-200 Certified) — Build & Launch a Microsoft Sentinel MDR Product

IT Partner LLCAnywherePosted 2w ago
Security Operations Analyst
Part-time
Remote
Apply on company siteCraft my tailored resume free

Free to start · No card

Job description

IT Partner LLC · Remote · Part-time (1–5 hrs/day) · Paid · 1-3-month residency with path to full-time About usIT Partner LLC is a Microsoft Cloud Solution Provider (CSP) — and 15+ years on the Microsoft Cloud. We're a US-based team that punches well above its weight by pairing deep Microsoft expertise with an AI-forward way of working. We support clients across the domestic US, remotely and on-site. The opportunityWe're launching a productized Managed Detection & Response (MDR) offering built on Microsoft Sentinel and Defender XDR, aimed at small and mid-sized businesses (20–50 seats). We're looking for a sharp, recently SC-200 certified engineer to help us build, test, and launch it on real customer environments. This isn't a coffee-and-copies internship. You'll own a real "founder's project" — turning our Sentinel/Defender capabilities into a repeatable, easy-to-sell product. It's a paid, flexible, month-long residency, and if it's a mutual fit, it converts into a full-time offer. What you'll do Stand up and configure a Microsoft Sentinel workspace with a standardized set of data connectors and analytics rules.Build a repeatable onboarding runbook so every client deployment is fast and identical.Develop and test SOAR playbooks (automated containment: account disable, token revocation, device isolation).Tune detections to reduce noise and maximize signal across Defender for Endpoint, Identity, Office, and Cloud Apps.Help package the offering into clean tiers with per-seat pricing, and pilot it on our SMB customer base.Document everything so we can scale it into a launched product.What you'll bringSC-200 (Microsoft Security Operations Analyst) certification — passed. ✅Genuine curiosity about SIEM/SOAR, Microsoft Sentinel, and Defender XDR.Comfort working hands-on in Microsoft 365 / Azure security tooling.Self-management and clear written communication (we work async).Bonus: KQL familiarity, PowerShell, or any Logic Apps / automation experience.What you'll getPaid hourly work, 1–5 hours/day on your own schedule — build it around classes or another job.Real production Sentinel/Defender experience on live tenants (the thing that actually gets you hired anywhere).Direct mentorship from a Microsoft CSP director and senior engineers.Portfolio artifacts (anonymized dashboards, playbooks, a case study) and a LinkedIn recommendation.Sponsorship toward your next Microsoft exam (SC-100, AZ-500, or MS-102).A clear path to full-time employment — this month is a real audition, for both of us.DetailsType: Part-time contract / paid internship (1 month, ~1–5 hrs/day)Location: RemoteStart: ASAPCompensation: Hourly (DOE) + full-time conversion opportunityReady to turn your SC-200 into a real, launched product on your résumé? Apply here or send a short note about why this project excites you — bonus points if you tell us one detection you'd build first.