Cybersecurity Lead Investigator

Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet

I korthet

Microsoft is seeking a Cybersecurity Lead Investigator to join the Detection and Response Team (DART). This customer-facing role involves leading complex, high-impact incident responses in on-premises and cloud environments, establishing technical priorities, and acting as the primary technical point of contact for customers. The position also includes research into security threats, contributing to thought leadership, and ensuring operational excellence.

Ansvarsområden

  • Orchestrate evidence-driven investigations and technical incident response.
  • Align specialist workstreams and communicate clear findings, priorities, and recommendations to customers.
  • Contextualize and prioritize findings to create a comprehensive account of security incident events.
  • Build and communicate a cohesive timeline of activity by pulling together multiple disparate events.
  • Collaborate with stakeholders at all business levels, including legal, compliance, cybersecurity, engineering, and executive functions.
  • Communicate key objectives and results with clarity and context.
  • Manage the complexities of large-scale cybersecurity investigations for global multinational organizations as the primary point of contact.
  • Lead research and analysis of security threats, sharing findings across the team.
  • Identify, conduct, and support research into critical security areas like current attacks, adversary tracking, and academic literature.
  • Analyze complex issues using multiple data sources to develop insights and identify security problems and threats.
  • Create new solutions to mitigate security issues.
  • Recommend prioritization and validation methods for technical indicators and develop tools to automate analyses.
  • Lead efforts to clean, structure, and standardize data and data sources, ensuring timely and consistent access.
  • Develop written content for publication on Microsoft blog platforms.
  • Develop presentations for delivery at internal and external conferences.
  • Use unique experiences from Microsoft Incident Response to create unique storytelling moments.
  • Complete operational tasks and readiness with timeliness and accuracy.
  • Follow Microsoft policies, compliance, and procedures.
  • Lead by example and guide team members on operational tasks, readiness, and compliance.

Krav

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
  • Requires verification of U.S. citizenship due to citizenship-based legal restrictions.
  • Ability to meet Microsoft, customer and/or government security screening requirements.
  • Must pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.

Önskade kvalifikationer

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
  • Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions.
  • Lead and manage high-profile incident response efforts for some of the world’s largest businesses.
  • Coordinate and lead all key stakeholders as the primary point of contact for major incidents.
  • Identify gaps early in the engagement process and request appropriate resources to fill those gaps.
  • Balance the need for rapid recovery with data collection and evidence preservation.
  • Direct activities to secure Enterprise-scale environments and assess potential data exfiltration or data collection.
  • Management of large-scale incidents in a follow-the-sun format working with fellow team members from across the globe.
  • Contextual application of MITRE Attack Framework and or OSI Model.
  • Delivery of complex and technical discussions effectively to customer representatives of varying levels.
  • Security Certifications in any of the following: OSCP, CISSP, SANS Certifications, SC Certifications from Microsoft.
  • Experience working with methods utilized for evidence collection, maintenance of chain of custody and associated documentation, evidence storage and analysis, and evidentiary reporting.
  • Eligibility to obtain or currently active government security clearance.
  • Experience analyzing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations.
  • Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability.
  • Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information.

Förmåner

  • Certain roles may be eligible for benefits and other compensation.
  • Applications accepted on an ongoing basis until the position is filled.
#security#incident response#cybersecurity#research#ai#cloud#threat analysis
Microsoft Logo

Om Microsoft

Empowering every person and organization on the planet to achieve more

Every company has a mission. What's ours? To empower every person and every organization to achieve more. We believe technology can and should be a force for good and that meaningful innovation contributes to a brighter world in the future and today. Our culture doesn’t just encourage curiosity; it embraces it. Each day we make progress together by showing up as our authentic selves. We show up with a learn-it-all mentality. We show up cheering on others, knowing their success doesn't diminish our own. We show up every day open to learning our own biases, changing our behavior, and inviting…

Microsoft Logo

Företag

Microsoft

Publicerade jobb

för 4 dagar sedan

Anställningstyp

Heltid

Arbetsform

Distans

Lön

119 800–234 700 US$ / år

Erfarenhetsnivå

Senior

Platser

United States

Kvalifikation

Doktorand, Masterexamen, Kandidatexamen

Sökande

Ansök tidigt