Sr Security Operations Engineer
Microsoft
Sr Security Operations Engineer
Multiple Locations, United States
Save
Overview
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world.
Microsoft is seeking a Senior Security Operations Engineer to join the Digital Security & Resilience (DSR) organization as we undergo the journey to ensure that the right virtualization services are released with the right security mindset. Our goal is to ensure access to the right resources at the right time, protected every step of the way.
With your experience in engineering, along with an understanding of Endpoint Security Vulnerability management (TVM, Antimalware, Website security), Enterprise infrastructure and overall Service Health, you will champion our own security-centric digital transformation. Your experience will support thousands of employees in improving Microsoft’s high standard of security.
A proficient candidate will have experience in a team environment, experience running enterprise scale services and platforms, technical depth in cloud platforms, agile development practices, and experience in designing & tuning telemetry. In addition, this position requires an individual who can develop and maintain highly resilient and scalable services through partnership with other teams.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
In alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day.
Qualifications
Required/Minimum Qualifications:
- Bachelor's Degree in Statistics, Mathematics, Computer Science or related field OR 5+ years of experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), and operations incident response.
- 5+ years technical engineering experience with programming, scripting language such PowerShell or Python, data engineering using sql and kql.
- Ability to obtain and maintain a US Security Clearance.
Other Requirements
Citizenship & Citizenship Verification: This position requires verification of U.S citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport.
Citizenship & Citizenship Verification: This role will require access to information that is controlled for export under U.S. export control regulations, potentially under the International Traffic in Arms Regulations or the Export Administration Regulations. As a condition of employment, the successful candidate will be required to provide proof of citizenship, for assessment of eligibility to access the export-controlled information. To meet this legal requirement, citizenship will be verified via a valid passport.
Cloud Screening:
This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
• Experience working on large scale services, components, or feature areas.
• Demonstrated understanding of monitoring, alerting, and observability philosophies and best practices.
• Knowledge of Endpoint Security and Microsoft Defender for Endpoint
• Collaborating first and foremost; ability to exercise cross-team co-operation and influence.
• Understanding of the frameworks such as MITRE ATT&CK, and NIST
• Experience working with PySpark or Pandas
• Experience working with any of the data platforms: Azure Data Factory, Azure Synapse Analytics, Databricks, Fabric.
• 5+ years of experience working in Azure, AWS or GCP clouds.
• 5+ years of experience with writing tools, automation, and enhancements to deliver and manage services in production.
• 5+ years of experience troubleshooting/debugging.
• 2+ years of working with services, responsible for gathering requirements, building, shipping, and operating a service.
• 2+ years of DevOps experience with a security first mindset.
• 2+ years of data analysis and visualization.
Security Operations Engineering IC4 - The typical base pay range for this role across the U.S. is USD $117,200 - $229,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $153,600 - $250,200 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay.
Microsoft will accept applications for the role until May 16th, 2025.
#MSRC #EndpointSecurity #Cybersecurity #VulnerabilityManagement #IAMProtect #SRE #SOE #MSFTSecurity
Responsibilities
• Adhere to modern engineering practices, enacting change to services through software engineering, unit testing, debugging, refactoring, code reviews and maintaining build/deployment pipelines.
• Identify opportunities and drive the implementation of automation to improve service health, manageability, reliability, and telemetry.
• Own, triage, investigate and resolve service issues with an emphasis on broad communication, learning & teaching throughout the process.
• Author functional and technical documentation. Communicate on a deep technical level with product engineering, project management and operations teams to improve. and optimize products, improve infrastructure, and evolve services.
• Remain current on new technologies, methods and procedures including, but not limited to, coding practices such as Test-Driven Development, Continuous Integration, and Continuous Deployment.
• Translate business requirements into technical specifications and help manage priorities, deliverables, and timelines.
You will be a service owner and will be responsible for all stages of the Software Development Lifecycle.