Security Operations Engineer
Summary
Designs, deploys, and maintains cloud/on-premises security controls to protect Microsoft’s global datacenter infrastructure (100+ sites, 1M+ servers) for services like Azure, Bing, and Office 365. Investigates threats, automates defenses, and collaborates cross-functionally to harden systems against cyberattacks.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day and we need you as a Security Operations Engineer.
Microsoft’s Cloud Operations & Innovation (CO+I) is the engine that powers our cloud services. As a Security Engineer you will perform a key role in delivering the core infrastructure and foundational technologies for Microsoft's online services including Bing, Office 365, Xbox, OneDrive, and the Microsoft Azure platform. You will implement and operate modern cloud and on premises cybersecurity controls to defend Microsoft datacenter critical infrastructure from threat actors. Leveraging multiple solutions and partnering with internal and external teams, you will be at the forefront of advancing industrial network cybersecurity capabilities.
Through on the job learning and bi-directional mentorship, this opportunity will allow you to gain cyber defense, automation, and networking skills and experiences that are rare in both networking and security organizations, and in high demand across multiple industries. This is a flexible work opportunity for you to work from home partially or fully if desired. As a group, CO+I is focused on personal and professional development for all employees and offers trainings and growth opportunities including Career Rotation Programs, Diversity & Inclusion trainings and events, and professional certifications.
Our infrastructure is comprised of a large global portfolio of more than 100 datacenters and 1 million servers. Our foundation is built upon and managed by a team of subject matter experts working to support services for more than 1 billion customers and 20 million businesses in over 90 countries worldwide.
With environmental sustainability and optimization at the forefront of our datacenter design and operations, we continue to grow and evolve as we meet the ever-changing business demands that hold Microsoft as a world-class cloud provider.
Do you want to empower billions across the world? Come and join us in CO+I and be at the forefront of the action!
Responsibilities
Responsibilities:
Incident Response Cyber Defense
- Lead and participate in security incident investigations across cloud, on-premises, and hybrid environments, including high-severity events and major incidents.
- Coordinate investigation and reponse activites with engineering, platrom, indentity, network, application and other partner teams.
- Develop and maintain incident response playbooks, procedures and operational runbooks.
- Improve Cyber Defense capabilities through process optimization, automation, lessons learned and recommendations that reduce security exposure.
Threat Detection & Security Operations
- Monitor, investigate and respond to security alerts using Microsoft Sentinel, Microsoft Defender XDR and other SIEM, EDR, and NDR technologies.
- Analyze attempted and successful compromises, perform proactive threat hunting and develop response and mitigation recommendations with partner teams.
- Create and tune detection rules, analytics, correlation logic and threat detection content usinf threat intelligence, indicators of compromise and adversary tactics, techniques and procedures.
- Use operational metrics and security data to improve detection fidelity, response times, service health and customer and partner experience, escalating gaps and recommending improvements as appropriate.
- Participate in an on-call rotation supporting security services and incident response.
Security Automation & Engineering
- Design and implement SOAR workflows, response automation, and operational tooling using PowerShell, Python, KQL, Logic Apps, Azure Functions, or equivalent technologies.
- Integrate security technologies and telemetry sources into security operations platforms to reduce analyst effort and improve investigation and response outcomes.
- Identify gaps and recurring issues in security controls, policies, and operational processes, then work with partner teams to implement consistent, scalable, and automated improvements.
Other
Embody our culture and values.
Qualifications
Required Qualifications:
3+ years of experience in cybersecurity, Security Operations Center operations, incident response, Cyber Defense, Blue Team functions, large-scale computing, software development, or a related technical field;
or A bachelor’s degree in computer science, Cybersecurity, Information Technology, Engineering, or a related field, or equivalent experience.
Experience investigating security incidents such as malware, credential compromise, unauthorized access, insider threats, or related malicious activity.
Knowledge of the incident response lifecycle, security monitoring, threat detection, and SIEM, EDR, or SOAR technologies.
Experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, Elastic, or comparable security platforms.
Hands-on experience with at least one scripting or security query language, such as KQL, PowerShell, or Python.
Understanding of network security and experience securing large-scale cloud environments, preferably Microsoft Azure.
Background Check Requirements:
Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
While not required, we also look for the following Preferred Qualifications:
- CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, PCCSE, PCNSE, PCSAE, CCNP Security, CCIE Security and/or Security+ certification.
- Any experience conducting investigations involving OT, manufacturing, critical infrasructure, energy or industrial enviroments is highly preferred (not mandatory)
- Experience securing large-scale Microsoft Azure environments
- Hands-on experience with multiple scripting or automation languages.
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.