Security Operations Engineer
Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity
In short
As a Security Operations Engineer with Microsoft's Cloud Operations & Innovation (CO+I) team, you will be responsible for defending Microsoft's cloud infrastructure from threat actors. This role involves leading incident investigations, performing threat detection using various security tools, and designing/implementing security automation workflows. The position offers a flexible work arrangement, with the option to work remotely.
Responsibilities
- Lead and participate in security incident investigations across cloud, on-premises, and hybrid environments.
- Develop and maintain incident response playbooks, procedures, and operational runbooks.
- Monitor, investigate, and respond to security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other SIEM, EDR, and NDR technologies.
- Analyze security alerts, perform threat hunting, and develop response recommendations.
- Create and tune detection rules, analytics, and threat detection content.
- Design and implement SOAR workflows, response automation, and operational tooling using PowerShell, Python, KQL, Logic Apps, or Azure Functions.
- Integrate security technologies and telemetry sources into security operations platforms.
- Identify gaps and recurring issues in security controls, policies, and operational processes, and work with partner teams to implement improvements.
Requirements
- 3+ years of experience in cybersecurity, Security Operations Center operations, incident response, Cyber Defense, Blue Team functions, large-scale computing, software development, or a related technical field; or a bachelor’s degree in computer science, Cybersecurity, Information Technology, Engineering, or a related field, or equivalent experience.
- Experience investigating security incidents such as malware, credential compromise, unauthorized access, insider threats, or related malicious activity.
- Knowledge of the incident response lifecycle, security monitoring, threat detection, and SIEM, EDR, or SOAR technologies.
- Experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, Elastic, or comparable security platforms.
- Hands-on experience with at least one scripting or security query language, such as KQL, PowerShell, or Python.
- Understanding of network security and experience securing large-scale cloud environments, preferably Microsoft Azure.
- Ability to meet Microsoft, customer and/or government security screening requirements.
Desired Qualifications
- CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, PCCSE, PCNSE, PCSAE, CCNP Security, CCIE Security and/or Security+ certification.
- Experience conducting investigations involving OT, manufacturing, critical infrastructure, energy or industrial environments is highly preferred.
- Experience securing large-scale Microsoft Azure environments.
- Hands-on experience with multiple scripting or automation languages.
Benefits
- Opportunity to gain cyber defense, automation, and networking skills and experiences.
- On the job learning and bi-directional mentorship.
- Focus on personal and professional development.
- Offers trainings and growth opportunities including Career Rotation Programs, Diversity & Inclusion trainings and events, and professional certifications.
#cybersecurity#security operations#incident response#cloud security#automation