Senior Incident Response Engineer

1 Week ago • 2-5 Years • Cyber Security

Job Summary

Job Description

The Senior Incident Response Engineer at Microsoft's Cybersecurity Incident Response Team (CIRT) investigates security incidents for enterprise customers. Responsibilities include analyzing, triaging, scoping, containing, and remediating security incidents; collecting and analyzing data to identify indicators of attack and compromise; collaborating with security and threat intelligence teams; and developing incident response runbooks. The role requires experience in cloud investigations (Entra ID, Microsoft 365, Microsoft Defender), customer support, and large enterprise environment support. The position offers flexible work arrangements (up to 100% remote).
Must have:
  • 2+ years Security Incident Response experience
  • 2+ years Cloud investigations experience
  • 2+ years customer facing experience
  • Experience supporting large enterprise environments
  • Network Security Administration experience
  • Bachelor's degree in relevant field
Good to have:
  • Experience in Entra ID and Microsoft 365 management
  • Experience with Microsoft Defender solutions
  • Azure Identity management and troubleshooting experience
  • Kusto Query Language knowledge
  • Cloud experience with major cloud providers
  • Automation experience (PowerShell, Python, etc.)
  • Relevant IT certifications
  • Linux and/or Mac administration experience
  • Fluency in Hebrew and English

Job Details

Overview

Interested in security and incident response? Then come join the Cybersecurity Incident Response Team (CIRT) at Microsoft as a Senior Incident Response Engineer responsible for helping customers investigate security incidents in their environment.

 

With over 18,000 employees worldwide, the Microsoft Customer Experience & Success (CE&S) organization is responsible for the strategy, design, and implementation of Microsoft’s end-to-end customer experience. Come join CE&S and help us build a future where customers come to us not only because we provide industry-leading products and services, but also because we provide a differentiated and connected customer experience.

 

Within CE&S, the Customer Service & Support (CSS) organization builds trust and confidence for every person and organization through delivering a seamless support experience. In CSS, we help customers and partners resolve their issues quickly, prevent future problems from occurring, and demonstrate new ways to achieve more from their Microsoft investment.

 

As a Senior Incident Response engineer, you will be an elite member of a customer facing security support team leading incident response investigations for Microsoft’s enterprise customers. You have experience in analysing, triaging, scoping, containing, providing guidance for remediation, and determining the root cause of security incidents. You are familiar with collecting and analysing security incident related data to identify indicators of attack and compromise.


In the Customer Service & Support (CSS) team we are looking for people with a passion for delivering customer success. As a Senior Incident Response Engineer you will own, troubleshoot and solve highly complex customer technical issues. This opportunity will allow you to accelerate your career growth by honing your problem-solving, collaboration and research skills, and developing your technical proficiency.


This role is flexible in that you can work up to 100% from home.


Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

 

Qualifications

Required/Minimum Qualifications (RQs/MQs)

 

  • Minimum 2+ years Security Incident Response experience with recent operational security experience (SOC, Malware Analysis, IDS/IPS Analysis, threat analytics, windows server, and endpoint security, etc.)
  • Minimum 2+ years Cloud investigations experience with Entra ID, Microsoft 365 and Microsoft Defender solutions
  • Minimum 2+ years customer facing experience - Customer Support experience preferred
  • Experience supporting large and complex geographically distributed enterprise environments with 1000+ users
  • Minimum 1+ years of experience in Network Security Administration, and/or Systems Administration with experience in Windows Server, Windows Client, and Active Directory Administration
  • Bachelor's degree in Computer Science, Information Technology (IT), or related field AND 5+ years of technical support, technical consulting experience, or information technology experience
  • Excellent written and spoken English language skills

 

 

Additional or Preferred Qualifications (PQs)

 

  • Experience in Entra ID and Microsoft 365 management and troubleshooting
  • Experience with any Microsoft Defender solutions
  • Experience in Azure Identity management and troubleshooting
  • Kusto Query Language knowledge
  • Cloud experience with any of the major cloud providers, including cloud security, networking, and migration of multi-cloud or hybrid deployments
  • Automation (PowerShell and/or Python, Java, or a similar language, can be a beginner to intermediate level).
  • Preferred IT Industry certifications (Microsoft Certifications On-Prem or Cloud, SANS GCIH, CISSP, CEH, Amazon AWS, etc.)
  • Preferred Bachelor’s degree or higher in a technical field, or relevant work experience
  • Experience in Linux and/or Mac administration

 

Language Qualification

 

Hebrew Language: fluent in reading, writing and speaking

English Language: fluent in reading, writing and speaking.


Ability to meet Microsoft, customer and / or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.

 

Responsibilities

Responsibilities:

 

  • Scope customer security incidents
  • Understand and identify indicators of attack and indicators of compromise
  • Analyse incident data from threat analytics tools
  • Collaborate with the Security and Threat Intelligence teams by providing indicators of compromise and samples of malware from the customer’s environment
  • Coordinate a response to the security incident with other Microsoft security and consulting teams.
  • Develop, document, and implement runbooks, capabilities, and techniques for Incident Response
  • Perform security triage and analysis on endpoint, server and network infrastructure.
  • Perform activities necessary for immediate containment and short-term resolution of incidents.
  • Maintain current knowledge and understanding of the threat landscape, emerging security threats, and vulnerabilities
  • Investigate root cause of complex security incidents
  • Maintain a high level of confidentiality
  • Participate in the on-call rotation as required

 

Similar Jobs

Glean - Solutions Architect ( EMEA/US East Customer hours )

Glean

Bengaluru, Karnataka, India (On-Site)
5 Months ago
ByteDance - Backend Software Engineer - Security Engineering

ByteDance

San Jose, California, United States (On-Site)
1 Week ago
Meta - Production Engineering

Meta

Cambridge, Massachusetts, United States (Hybrid)
5 Months ago
Google - Senior Technical Solutions Consultant, Auto/Maps

Google

Tokyo, Japan (On-Site)
1 Week ago
PlayStation Global - Software Engineering Manager, Android

PlayStation Global

Carlsbad, California, United States (On-Site)
3 Days ago
PwC - L3 SIEM (Security Information and Event Management) SME

PwC

Kuala Lumpur, Federal Territory Of Kuala Lumpur, Malaysia (On-Site)
6 Months ago
Fluence - Cybersecurity Engineer (m/f/d)

Fluence

Erlangen, Bavaria, Germany (Hybrid)
6 Months ago
SmileGate - Information Security: Security Solution Architect and Operations

SmileGate

Seongnam-si, Gyeonggi-do, South Korea (On-Site)
1 Month ago
PwC - IN_Manager _Technical Delivery Manager_ Emerging Technologies_ Advisory_ Bengaluru

PwC

Bengaluru, Karnataka, India (On-Site)
6 Months ago
Google - Security Engineer, AI Agent Security

Google

Zürich, Zurich, Switzerland (On-Site)
1 Week ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Go Fund Me - Senior DevEx Engineer

Go Fund Me

Buenos Aires, Buenos Aires, Argentina (Remote)
1 Month ago
ION - Senior Technical Consultant - Endur

ION

Houston, Texas, United States (On-Site)
6 Months ago
Google - Business Analyst, Creator Partnerships, YouTube

Google

San Bruno, California, United States (On-Site)
1 Week ago
Zazz - Java Developer

Zazz

(Remote)
2 Months ago
Netflix - Software Engineer L4 - Finance and Tax Technology

Netflix

Warsaw, Masovian Voivodeship, Poland (Hybrid)
3 Months ago
N-iX - Senior Scala Engineer

N-iX

Ukraine (Remote)
1 Month ago
Ello - Senior Unity Engineer (Contract)

Ello

São Paulo, State Of São Paulo, Brazil (Hybrid)
1 Month ago
Google - Senior Software Engineer, Full Stack, VM Manager

Google

Warsaw, Masovian Voivodeship, Poland (On-Site)
1 Week ago
Epic Games - Backend Engineer

Epic Games

(On-Site)
1 Month ago
ByteDance - Senior Software Engineer

ByteDance

San Jose, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Tel Aviv-Yafo, Tel Aviv District, Israel

Booming games - Business Development Manager

Booming games

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
2 Months ago
NVIDIA - Senior Malware Research Architect

NVIDIA

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
3 Months ago
Google - Senior Hardware Emulation Engineer

Google

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
1 Week ago
NVIDIA - Senior Chip Design Engineer

NVIDIA

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
1 Month ago
NVIDIA - Senior Software Engineer - Ethernet Switch

NVIDIA

Ra'anana, Center District, Israel (Hybrid)
3 Months ago
NVIDIA - Software Manager, DOCA Verification

NVIDIA

Yokne'am Illit, North District, Israel (On-Site)
1 Month ago
NVIDIA - Senior Software Research Architect

NVIDIA

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
1 Month ago
NVIDIA - Software Verification Manager

NVIDIA

Yokne'am Illit, North District, Israel (On-Site)
3 Months ago
NVIDIA - Senior System Software Architect, HPC Networking

NVIDIA

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
1 Month ago
Playtika - User Acquisition Manager - Bingo Blitz

Playtika

Israel (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Cyber Security Associate

PwC

Bangkok, Bangkok, Thailand (On-Site)
6 Months ago
ByteDance - Software Engineer Intern, Security Engineering

ByteDance

Singapore (On-Site)
1 Month ago
PwC - Cyber Security Associate (New Graduate)

PwC

Bangkok, Bangkok, Thailand (On-Site)
2 Months ago
PwC - Workday reporting Sr.

PwC

Buenos Aires, Buenos Aires, Argentina (On-Site)
6 Months ago
ByteDance - Senior Security Software Architect, Security Engineering

ByteDance

Singapore (On-Site)
5 Months ago
Google - Senior Red Team Security Consultant

Google

Atlanta, Georgia, United States (On-Site)
1 Week ago
Google - Engineering Manager, Google Distributed Cloud air-gapped

Google

Sunnyvale, California, United States (On-Site)
1 Week ago
NVIDIA - Network Security Research Architect

NVIDIA

United Kingdom (Remote)
1 Month ago
Accurate - Information Security Engineer

Accurate

Hyderabad, Telangana, India (Hybrid)
6 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

Noida, Uttar Pradesh, India (On-Site)

Redmond, Washington, United States (Hybrid)

Hyderabad, Telangana, India (On-Site)

Bengaluru, Karnataka, India (On-Site)

Hyderabad, Telangana, India (On-Site)

Redmond, Washington, United States (Remote)

Cairo, Cairo Governorate, Egypt (On-Site)

Budapest, Hungary (Hybrid)

View All Jobs

Get notified when new jobs are added by Microsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug