Required/minimum qualifications
- Bachelor's Degree in Statistics, Mathematics, Computer Science or related field
- OR 5+ years of experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), and operations incident response.
5+ years of experience working with adversary & cyber intel frameworks such as kill-chain model, ATT&CK framework, and Diamond Model.
3+ years' experience with big data and Security Information & Event Management (SIEM) solutions such as ArcSight, Splunk, ElasticSearch, Logstash, Azure Data Explorer, Azure Log Analytics, Azure Data Lake, or Azure Sentinel.
3+ years' experience working with extremely large data sets to answer complex and ambiguous questions, using tools and languages like: SQL, KQL, Jupyter Notebook, Spark, Azure Synapse, R, U-SQL, Python, Splunk, and PowerBI
Asstatedin the job posting, this position requires verification of citizenship or other protected status to meetlegalrequirements of the role. If the role requires US citizenship, as indicated in the job description, a valid US passport must be provided to verify your citizenship.Can you meet therequirementstatedin the job description?
Other RequirementsAbility to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Citizenship & Citizenship Verification: This position requires verification of U.S citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government clearance.
Additional or preferred qualifications- Master's Degree or Doctorate in Statistics, Mathematics, Computer Science or related field
- OR 7+ years of experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and anomaly detection.
- CISSP CISA CISM SANS GCIA GCIH OSCP Security+
- Previous experience performing development and code debugging with functional or object-oriented programming such as .NET or Java.
- Expectation to learn new tools and techniques every day. - Good working knowledge of common security, encryption, and protocols such as encryption, PKI, modern authentication and cloud app authorization architectures and protocols such as SAML or OAUTH.
- Past experience working in large scale enterprise products: Azure or M365 products such as Exchange, SharePoint, Skype, Teams.
- Deep and practical OS security/internals knowledge for Linux and Windows.
- Exposure to security related subjects and trends such as digital forensics, reverse engineering, penetration testing, and malware analysis.
- Ability to rapidly automate data handling and data curation using PowerShell, Python, Azure Data Factory, and various Azure-based tools.
- Hands-on experience building Azure-based services with Azure Resource Manager (ARM), ARM templates, ARM policy, IaaS, VMSS, KeyVault, EventHub, Azure Active Directory (AAD), etc.
- Hands-on experience with Continuous Integration/Continuous Delivery (CI/CD), Azure DevOps and Agile Scrum.
- Certifications like GCIA, GSLC, GCIH, CISM, CISSP, CEH, etc. are plus
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:Microsoft will accept applications for the role until July 23, 2025.