Senior Security Operations Engineer

Microsoft
Redmond, WA, United States
6 days ago
Apply on www.jobmonkeyjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$119,800.0 - $234,700.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Microsoft Online Services C Sharp (Programming Language) C++ (Programming Language) Cyber Security Computer Programming Data Integration Decision Support Systems Domain Name System (DNS) Intrusion Detection and Prevention Virtual Private Networks (VPN) Python (Programming Language)
+16 more
Network Troubleshooting Live Connect (Windows) Routing Windows PowerShell Kusto Query Language Security Information and Event Management Software Engineering TCP/IP Workflow Management Systems Data Ingestion Microsoft Power Automate Large Language Models Firewalls (Computer Science) Information Technology Microsoft Sentinel Security Orchestration, Automation & Response

Job description

We are looking to hire a Senior Security Operations Engineer that brings broad technical experience across security, networking, and operations; deliver impactful projects in ambiguous environments; and demonstrate a bias for action and commitment to continuous learning.

This role requires broad technical capability, sound judgment when handling sensitive issues, and the ability to deliver results in a fast-moving, operationally focused environment.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

  • Implement AI-enabled SOC automation and investigation capabilities, including signal enrichment, workflow orchestration, and analyst tooling.

  • Develop and operate the security tooling, data integrations, dashboards, and supporting platforms required for reliable day-to-day security operations.

  • Tune detections and investigation workflows to improve signal quality, reduce false positives, shorten investigation time, and increase analyst productivity.

  • Participate in incident investigation and response, maintain operational readiness, and troubleshoot security issues affecting network, infrastructure, and physical security services.

  • Partner with engineering, facilities, networking, and security teams to automate manual processes, resolve operational issues, and strengthen end-to-end resilience.

Requirements

  • Doctorate in Statistics, Mathematics, Computer Science, or related field
  • OR Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
  • OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
  • OR equivalent experience.

Other Requirements

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings
  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.
  • Citizenship & Citizenship Verification: This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR), the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide either proof of their country of citizenship or proof of their U.S. permanent residency or other protected status (e.g., under 8 U.S.C. § 1324b(a)(3)) for assessment of eligibility to access the export-controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable., * Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
  • OR Master’s Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
  • OR Bachelor’s Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
  • OR equivalent experience.
  • CISSP CISA CISM SANS OSCP Security
  • 2+ years of experience programming in C++/C# or Python or Scala or similar technologies.
  • Demonstrated experience coordinating incidents and supporting live services, including investigation, containment, recovery, escalation, triage, root-cause analysis, stakeholder communication, and operational readiness.
  • Hands-on experience with Microsoft Sentinel (KQL) or an equivalent enterprise SIEM, including detection engineering, data onboarding, investigative analysis, and resolution of ambiguous, high-impact security issues.
  • Hands-on experience with security automation and AI-assisted operational workflows using PowerShell, Python, Logic Apps, or similar technologies for signal enrichment, investigations, workflow orchestration, and decision support.
  • Working knowledge of enterprise networking, including DNS, TCP/IP, firewalls, routing, VPNs, and network troubleshooting.
  • Experience working with SOC, NOC.
  • Experience collaborating with corporate insider threat, investigations, legal, or trade compliance functions; exposure to dedicated insider threat platforms such as Purview, DTEX, Proofpoint ITM, Magnet Axiom, or Forcepoint.
  • Experience designing, deploying, or evaluating agentic AI or LLM-based automation in a security operations context.
  • Experience or interest in the specific challenges of protecting strategic research programs from sustained external targeting; familiarity with export control (EAR / ITAR) and government program environments.

Quantum #QuantumCareers #MDQCareers

About the company

Quantum computing has the potential to massively accelerate science and technology innovation. Microsoft Discovery & Quantum group is building advanced computing platforms, spanning HPC, AI, and quantum, to realize that future. You will join the Quantum Security & IT Operations (QSIT) team protecting a globally distributed research community and its intellectual property.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobmonkeyjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:06 min

Ingesting streaming data securely with managed hubs

Eldert Grootenboer +1 · World Congress 2023

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

1:49 min

One-way data ingestion for IoT devices

Timothy Marland · World Congress 2023

1:51 min

Overview of the three Google Maps routing applications

Germán Álvarez · LIVE

Videos

See all

Related articles

See all