Incident Response Engineer - CIRT

2 Weeks ago • 7 Years + • Cyber Security

Job Summary

Job Description

As a Senior Incident Response Engineer in Microsoft's Customer Service & Support (CSS) team, you'll be a key member of a customer-facing security support team. Responsibilities include leading incident response investigations for enterprise customers, analyzing and triaging security incidents, containing threats, providing remediation guidance, and determining root causes. You'll work with threat analytics tools, collaborate with security teams, and develop incident response runbooks. The role requires experience in cloud investigations (Entra ID, Microsoft 365, Defender), network security administration, and system administration (Windows Server, Client, Active Directory). You'll need expertise in Azure Identity management, Kusto Query Language, and automation (PowerShell/Python). This is a fully remote role.
Must have:
  • 5+ years experience or Bachelor's degree + 2 years experience
  • 2+ years Security Incident Response experience
  • 2+ years Cloud investigations experience
  • Experience with Microsoft Defender solutions
  • Kusto Query Language knowledge
Good to have:
  • Linux/Mac administration
  • IT Certifications (Microsoft, SANS GCIH, CISSP, etc.)
  • PowerShell and/or Python
  • Bachelor's degree in technical field

Job Details

Overview

With over 17,000 employees worldwide, the mission of the Customer Experience & Success (CE&S) organization is to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft’s products and services, ignited by our people and culture. Come join CE&S and help us build a future where customers achieve their business outcomes faster with technology that does more.

 

Within CE&S, the Customer Service & Support (CSS) organization builds trust and confidence for every person and organization through delivering a seamless support experience. In CSS, we are powered by Microsoft’s AI technology to help consumers, businesses, partners, and more, resolve their issues quickly and securely, helping prevent future problems from occurring and achieving more from their Microsoft investment.


As a Senior Incident Response engineer, you will be an elite member of a customer facing security support team leading incident response investigations for Microsoft’s enterprise customers. You have experience in analysing, triaging, scoping, containing, providing guidance for remediation, and determining the root cause of security incidents. You are familiar with collecting and analysing security incident related data to identify indicators of attack and compromise.

 

In the Customer Service & Support (CSS) team we are looking for people with a passion for delivering customer success. As a Senior Incident Response Engineer you will own, troubleshoot and solve highly complex customer technical issues. This opportunity will allow you to accelerate your career growth by honing your problem-solving, collaboration and research skills, and developing your technical proficiency.

 

This role is flexible in that you can work up to 100% from home.


Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

 

Qualifications

Required Qualifications:
• Bachelor's degree in Computer Science, Information Technology (IT), or related field AND 5+ years of technical support, technical consulting experience, or information technology experience 
     o OR 7+ years of technical support, technical consulting experience, or information technology experience. 
     o OR equivalent experience
 
 
• Minimum 2+ years Security Incident Response experience with recent operational security experience (SOC, Malware Analysis, IDS/IPS Analysis, threat analytics, windows server, and endpoint security, etc.)
• Minimum 2+ years Cloud investigations experience with Entra ID, Microsoft 365 and Microsoft Defender solutions
• Minimum 2 years customer facing experience
• Experience supporting large and complex geographically distributed enterprise environments with 1000+ users
• Minimum 1+ years of experience in Network Security Administration, and/or Systems Administration with experience in Windows Server, Windows Client, and Active Directory Administration
 
• Experience in Entra ID and Microsoft 365 management and troubleshooting
• Experience with any Microsoft Defender solutions
• Experience in Azure Identity management and troubleshooting
• Kusto Query Language knowledge
• Cloud experience with any of the major cloud providers, including cloud security, networking, and migration of multi-cloud or hybrid deployments
• Automation (PowerShell and/or Python, Java, or a similar language, can be a beginner to intermediate level).
• Preferred IT Industry certifications (Microsoft Certifications On-Prem or Cloud, SANS GCIH, CISSP, CEH, Amazon AWS, etc.)
• Preferred Bachelor’s degree or higher in a technical field, or relevant work experience
Experience in Linux and/or Mac administration
 
 
Ability to meet Microsoft, customer and / or government security screening requirements are required for this role.  These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.
 

Responsibilities

• Scope customer security incidents
• Understand and identify indicators of attack and indicators of compromise
• Analyse incident data from threat analytics tools
• Collaborate with the Security and Threat Intelligence teams by providing indicators of compromise and samples of malware from the customer’s environment
• Coordinate a response to the security incident with other Microsoft security and consulting teams.
• Develop, document, and implement runbooks, capabilities, and techniques for Incident Response
• Perform security triage and analysis on endpoint, server and network infrastructure.
• Perform activities necessary for immediate containment and short-term resolution of incidents.
• Maintain current knowledge and understanding of the threat landscape, emerging security threats, and vulnerabilities
• Investigate root cause of complex security incidents
• Maintain a high level of confidentiality
* Participate in the on-call rotation as required

Similar Jobs

Google - Senior Software Engineer, Storage, Pixel Software

Google

New Taipei, New Taipei City, Taiwan (On-Site)
2 Weeks ago
Google - Software Engineering Manager II, Google Ads

Google

Irvine, California, United States (On-Site)
2 Weeks ago
Ettain Group - Automation Developer/Engineer

Ettain Group

Dallas, Texas, United States (On-Site)
10 Years ago
ByteDance - Tech Lead Software Engineer- Programming Language (San Jose, CA)

ByteDance

San Jose, California, United States (On-Site)
4 Months ago
Google - Software Engineer III, Full Stack, YouTube OTT

Google

Bengaluru, Karnataka, India (On-Site)
1 Week ago
Barracuda Networks  Inc  - Senior Security Engineer

Barracuda Networks Inc

Bengaluru, Karnataka, India (On-Site)
6 Months ago
Microsoft - Software Engineer - Security

Microsoft

Redmond, Washington, United States (On-Site)
2 Weeks ago
PwC - CISO Information Security Associate

PwC

Bangkok, Bangkok, Thailand (On-Site)
3 Weeks ago
Trend Micro - Sr. Engineer

Trend Micro

Taipei City, Taiwan (On-Site)
7 Months ago
Axinous - Principal Professional Services Architect (Data Loss Prevention)

Axinous

Hyderabad, Telangana, India (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Extreme Inc. - System Engineer

Extreme Inc.

Tokyo, Japan (Hybrid)
1 Day ago
Glean - Solutions Engineer

Glean

(Remote)
7 Hours ago
ION - Senior Full Stack Software Developer, Italy

ION

Pisa, Tuscany, Italy (On-Site)
6 Months ago
Next Level Business Services - CQ5 Developer/Architect

Next Level Business Services

Sunnyvale, California, United States (On-Site)
6 Months ago
ION - Senior IT Architect, Italy

ION

Italy (Hybrid)
6 Months ago
Push Gaming - Information Security Analyst

Push Gaming

Malta (Remote)
2 Weeks ago
Bigpoint - Lead Game Developer

Bigpoint

Hamburg, Hamburg, Germany (Remote)
3 Months ago
DailyWire - Senior Software Engineer

DailyWire

Nashville, Tennessee, United States (On-Site)
3 Weeks ago
Zeta - Manager - Software Development

Zeta

Bengaluru, Karnataka, India (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Sydney, New South Wales, Australia

Canva - B2B Growth Marketing Specialist, Enterprise

Canva

Sydney, New South Wales, Australia (Remote)
3 Weeks ago
Nine - Account Executive

Nine

North Sydney, New South Wales, Australia (On-Site)
3 Days ago
Canva - Security Engineering Manager - Vulnerability Management, Application Security

Canva

Surry Hills, New South Wales, Australia (Remote)
2 Weeks ago
Canva - Backend Software Engineer - Gen AI, Design Generation Experience

Canva

Brisbane, Queensland, Australia (Remote)
4 Weeks ago
Canva - Staff Frontend Engineer - Apps API Platform

Canva

Brisbane, Queensland, Australia (Remote)
1 Month ago
Immutable - Product Designer, Experimentation

Immutable

Sydney, New South Wales, Australia (Hybrid)
1 Day ago
PlayStation Global - Senior Linux Network Software Engineer

PlayStation Global

Adelaide, South Australia, Australia (On-Site)
1 Month ago
Canva - Senior Software Engineer - Identity & Access

Canva

Surry Hills, New South Wales, Australia (Remote)
1 Month ago
Canva - Senior Software Engineer - Cloud Access Team

Canva

Sydney, New South Wales, Australia (Remote)
1 Week ago
Aristocrat Gaming - Animator

Aristocrat Gaming

North Ryde, New South Wales, Australia (Hybrid)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ByteDance - Security Engineer (Penetration Tester) - 2025 Start

ByteDance

Singapore (On-Site)
6 Months ago
PwC - 1-10yrs Application for Cyber- Kolkata DN 57 - RDC

PwC

Kolkata, West Bengal, India (On-Site)
7 Months ago
ByteDance - Cloud Security Architect

ByteDance

Singapore (On-Site)
2 Weeks ago
ION - IT/Cyber Security Analyst

ION

London, England, United Kingdom (On-Site)
6 Months ago
ION - Security Architect, Italy

ION

Italy (Hybrid)
6 Months ago
ByteDance - Software Engineer - Network Security - San Jose

ByteDance

San Jose, California, United States (On-Site)
6 Months ago
Google - Staff Software Engineer, Product Security Engineering, Cloud CISO

Google

Kirkland, Washington, United States (On-Site)
1 Week ago
ByteDance - Senior Security System Engineer

ByteDance

Dubai, Dubai, United Arab Emirates (On-Site)
2 Weeks ago
Easy Brain - Information Security Officer

Easy Brain

Limassol, Limassol, Cyprus (Hybrid)
2 Months ago
PwC - IN-Senior Manager – ERP - Sales-Ms Dynamics– Advisory  - Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Microsoft is a tech giant that develops, licenses, and supports a range of software products, services, and devices.

London, England, United Kingdom (On-Site)

Redmond, Washington, United States (On-Site)

Redmond, Washington, United States (Hybrid)

Shanghai, Shanghai, China (Hybrid)

Beijing, Beijing, China (On-Site)

Washington, United States (On-Site)

Phoenix, Arizona, United States (On-Site)

Penang, Malaysia (On-Site)

London, England, United Kingdom (On-Site)

View All Jobs

Get notified when new jobs are added by Microsoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug