Required Qualifications:
- Bachelor's Degree in Statistics, Mathematics, Computer Science or related field OR 5+ years of experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), and operations incident response.
- 5+ years of Extensive Incident Response Experience
- 5+ years of experience in Security Engineering, with demonstrated proficiency in security architecture, threat detection, and automation.
Other Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
- This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
- Citizenship Verification: This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide either proof of their country of citizenship or proof of their U.S. permanent residency or other protected status (e.g., under 8 U.S.C. 1324b(a)(3)) for assessment of eligibility to access the export controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.
- Citizenship Verification:This position requires verification of citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport.
Preferred Qualifications:
- Proven track record of leading complex security incidents across cloud and on-premises environments, including containment, eradication, and recovery.
- Cross-Organizational Coordination: Experience developing and implementing incident response frameworks that span multiple business domains such as Healthcare, Legal, and Human Resources.
- Proficiency in scripting languages (e.g., Python, PowerShell, Bash) and familiarity with SIEM/SOAR platforms.
- Regulatory & Compliance Awareness:Understanding of regulatory frameworks such as HIPAA, SOC 2, PCI, and HITRUST, and how they impact incident response and audit readiness.
- Threat Modeling & Risk Analysis: Ability to partner with threat modeling teams and develop logging and telemetry standards to support proactive detection and investigation.
- Automation & Process Optimization - Experience designing automated workflows to reduce detection and response times and integrating security processes into CI/CD pipelines.
- Stakeholder Engagement: Skilled in working with cross-functional teams including engineering, legal, HR, and compliance to align incident response strategies and governance.
- Mentorship & Enablement: Demonstrated ability to mentor early-career analysts and responders in security principles, incident handling, and post-incident analysis.
- Communication & Influence: Effective verbal and written communication skills, with the ability to influence decision making and drive alignment across diverse teams.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
Microsoft will accept applications for the role until October 7, 2025.