About the job
The Global Customer Success (GCS) organization, an organization within CE&S, is leading the effort to enable customer success on the Microsoft Cloud by harnessing leading, AI-powered capabilities and human expertise to deliver innovation solutions that accelerate business value, drive operational excellence and nurture long term loyalty.
Are you looking for an exciting opportunity to lead Microsoft's response efforts to protect over a billion customers around the world? Are you excited about cybersecurity and ready to join a passionate security response team dedicated to protecting customers from emerging cybersecurity threats? If so, this role may be your next opportunity. Microsoft Detection and Response Team (DART) is looking for a motivate and experienced security professional to Lead and manage all aspects of Cybersecurity Incident Response engagements.
The Team Lead plays a vital role in responding to major cybersecurity incidents. They guide multi-functional teams through the incident response process, ensuring a balance between speed of recovery, evidence preservation, and security of the restoration process. As a Lead Investigator, you’ll operate like the conductor of an orchestra, coordinating actions and adapting quickly to complex situations.
This role is flexible in that you can work up to 100% from home.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
- Elevates findings to address and mitigate issues.
- Balances dissemination value with the risk of divulging techniques.
- Collaborates to incorporate findings into future designs and analyses.
- Leads data quality efforts for timely and consistent data access.
- Cleans, structures, and standardizes data sources.
- Schedules analysis for multiple feature areas.
- Develops guidelines, models, and best practices to avoid common issues.
- Architects solutions and automation for security issues.
- Drives development of guidance and education from security resolutions.
- Advocates for key security issues and mitigations.
- Promotes security practices across the company.
- Leads postmortem and root-cause analyses for complex issues.
- Ensures best practices for security architecture, design, and development.
- Leads incident response efforts during cybersecurity incidents.
- Identifies gaps and requests resources to fill them.
- Coordinates with teams to ensure timely and complete engagement.
- Balances rapid recovery with data collection and evidence preservation.
- Manages large-scale incidents with global team collaboration.
- Applies MITRE Attack Framework and OSI Model.
- Embodies company culture and values.
Minimum required qualifications
- Doctorate in Statistics, Mathematics, Computer Science, or related field OR 7+ years in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection.
- 3+ years in cybersecurity incident response investigation.
- 7+ years in consulting.
- Security certifications: OSCP, CISSP, SANs, or SC from Microsoft.
- Effective delivery of complex technical discussions to various customer levels.
- Experience in evidence collection, chain of custody, evidence storage, analysis, and reporting.
- Eligibility or active government security clearance.
Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about .