1 day ago
Base Salary
$120k - $261k/yr
Responsibilities
- Implement AI-enabled SOC automation and investigation capabilities, including signal enrichment, workflow orchestration, and analyst tooling.
- Develop and operate security tooling, data integrations, dashboards, and supporting platforms for daily security operations.
- Tune detections and investigation workflows to improve signal quality, reduce false positives, shorten investigation time, and increase analyst productivity.
- Participate in incident investigation and response, maintain operational readiness, and troubleshoot issues affecting network, infrastructure, and physical security services.
- Partner with engineering, facilities, networking, and security teams to automate manual processes, resolve operational issues, and strengthen resilience.
Requirements
- Doctorate in Statistics, Mathematics, Computer Science, or a related field; or a master’s degree with 3+ years of relevant experience; or a bachelor’s degree with 4+ years of relevant experience; or equivalent experience.
- 2+ years of programming experience in C++, C#, Python, Scala, or similar technologies.
- Experience coordinating incidents and supporting live services, including investigation, containment, recovery, escalation, triage, root-cause analysis, stakeholder communication, and operational readiness.
- Hands-on experience with Microsoft Sentinel and KQL, or an equivalent enterprise SIEM, including detection engineering, data onboarding, investigative analysis, and resolving ambiguous security issues.
- Hands-on experience with security automation and AI-assisted workflows using PowerShell, Python, Logic Apps, or similar technologies.
- Working knowledge of enterprise networking, including DNS, TCP/IP, firewalls, routing, VPNs, and network troubleshooting.
- Experience working with SOC and NOC environments.
- Preferred qualifications include a doctorate with 3+ years, a master’s degree with 6+ years, or a bachelor’s degree with 8+ years of relevant experience, or equivalent experience.
- Preferred qualifications include CISSP, CISA, CISM, SANS, or OSCP credentials; experience with insider threat, investigations, legal, or trade compliance functions; and experience with agentic AI or LLM-based security automation.
- Ability to meet Microsoft, customer, and government security screening requirements, including the Microsoft Cloud Background Check and export-control citizenship or protected-status verification.
Benefits
- The typical U.S. base pay range is USD $119,800–$234,700 per year, with a separate San Francisco Bay Area and New York City metropolitan area range of USD $160,200–$261,000 per year.
- Certain roles may be eligible for benefits and other compensation.
- The position is open for at least five days, with applications accepted on an ongoing basis until filled.
About Microsoft
Microsoft develops operating systems, productivity software, cloud services, developer tools, and consumer devices for individuals, enterprises, and governments. Its main products include Windows, Microsoft 365, Azure, Visual Studio/GitHub, Xbox, and LinkedIn; revenue comes from software subscriptions and licenses, cloud consumption, hardware sales, and advertising. Founded in 1975 and headquartered in Redmond, Washington, Microsoft is a public company traded on Nasdaq.
