Security Operations Engineer

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity

In short

As a Security Operations Engineer with Microsoft's Cloud Operations & Innovation (CO+I) team, you will be responsible for defending Microsoft's cloud infrastructure from threat actors. This role involves leading incident investigations, performing threat detection using various security tools, and designing/implementing security automation workflows. The position offers a flexible work arrangement, with the option to work remotely.

Responsibilities

  • Lead and participate in security incident investigations across cloud, on-premises, and hybrid environments.
  • Develop and maintain incident response playbooks, procedures, and operational runbooks.
  • Monitor, investigate, and respond to security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other SIEM, EDR, and NDR technologies.
  • Analyze security alerts, perform threat hunting, and develop response recommendations.
  • Create and tune detection rules, analytics, and threat detection content.
  • Design and implement SOAR workflows, response automation, and operational tooling using PowerShell, Python, KQL, Logic Apps, or Azure Functions.
  • Integrate security technologies and telemetry sources into security operations platforms.
  • Identify gaps and recurring issues in security controls, policies, and operational processes, and work with partner teams to implement improvements.

Requirements

  • 3+ years of experience in cybersecurity, Security Operations Center operations, incident response, Cyber Defense, Blue Team functions, large-scale computing, software development, or a related technical field; or a bachelor’s degree in computer science, Cybersecurity, Information Technology, Engineering, or a related field, or equivalent experience.
  • Experience investigating security incidents such as malware, credential compromise, unauthorized access, insider threats, or related malicious activity.
  • Knowledge of the incident response lifecycle, security monitoring, threat detection, and SIEM, EDR, or SOAR technologies.
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, Elastic, or comparable security platforms.
  • Hands-on experience with at least one scripting or security query language, such as KQL, PowerShell, or Python.
  • Understanding of network security and experience securing large-scale cloud environments, preferably Microsoft Azure.
  • Ability to meet Microsoft, customer and/or government security screening requirements.

Desired Qualifications

  • CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, PCCSE, PCNSE, PCSAE, CCNP Security, CCIE Security and/or Security+ certification.
  • Experience conducting investigations involving OT, manufacturing, critical infrastructure, energy or industrial environments is highly preferred.
  • Experience securing large-scale Microsoft Azure environments.
  • Hands-on experience with multiple scripting or automation languages.

Benefits

  • Opportunity to gain cyber defense, automation, and networking skills and experiences.
  • On the job learning and bi-directional mentorship.
  • Focus on personal and professional development.
  • Offers trainings and growth opportunities including Career Rotation Programs, Diversity & Inclusion trainings and events, and professional certifications.
#cybersecurity#security operations#incident response#cloud security#automation
Microsoft Logo

Company

Microsoft

Job Posted

1 month ago

Employment Type

Full Time

WorkMode

Remote

Experience Level

Mid-Senior

Applicants

Be an early applicant