Are you looking for a challenge that puts you at the center of the Microsoft Edge + Platform Security Fundamentals (EPSF) strategy? Are you passionate about solving the security challenges of critical online services? Are you passionate about defensive and offensive security? Microsoft's EPSF (Edge + Platform Security Fundamentals) team is responsible for securing some of Microsoft's largest and most influential online services in the Azure Edge & Platform (AEP) organization and Windows Devices organization (W+D). The EPSF Services Pentest (SERPENT) team needs a Senior Security Operations Engineer to increase our business partners' security posture.
Key Responsibilities:
- Security Incident Response: Analyze and respond to security incidents, develop response plans, and conduct postmortem analysis.
- Identification and Detection of Control Failures: Design solutions to address control issues and improve security posture.
- Automation: Recommend and implement automation to improve security operations efficiency.
- Monitoring and Detection: Build new detection capabilities and drive automation of detection and response.
- Threat Intelligence and Analysis: Recommend detections and signatures based on industry threat trends.
- Data-Driven Analysis: Analyze key metrics and KPIs to recommend mitigation strategies.
- Penetration Testing: Understand and leverage weaponized code and tactical tools for security operations.
Required Qualifications:
- 5+ years of experience in software development lifecycle, large-scale computing, cyber security, anomaly detection, SOC detection, threat analytics, SIEM, IT, and operations incident response OR Bachelor's Degree in related field.
- Cloud Background Check and Microsoft Cloud Background Check required.
Preferred Qualifications:
- 7+ years of experience or Master's/Doctorate in related field.
- Certifications such as CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, and/or Security+.
- Experience in technical disciplines outside security, including software development, networking, and database management.
- Coding skills in languages like C#, C++, Ruby, Python, etc.
- Experience with web services, OWASP top 10 security flaws, and understanding complex systems.
- Networking/Identity Isolation, Active Directory, operational security, and Linux skills.
This role offers a competitive salary range and comprehensive benefits package, including industry-leading healthcare, educational resources, and opportunities for professional growth.