Verified current Job

Cybersecurity Lead Investigator

Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery a...

Job Full source details
Microsoft US Source published Oct 1, 2026 Verified 12 hours ago
✓ 95% verification score · Source: Microsoft Careers · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
Cybersecurity Lead Investigator opportunity at Microsoft
DeadlineTue Mar 30 8:31 PM 2027
EmploymentF U L L T I M E
CountryUS

Overview

Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers. Technical Delivery This role will work as part of a collaborative team assisting our top customers with: Contextualizing and prioritizing findings to put together a comprehensive account and briefing of the events that transpired during a security incident. Pulling together multiple disparate events to build and communicate a cohesive timeline of activity. Collaborating with stakeholders at every level of the business, including legal,

Full job description

Full Job Description

Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers. Technical Delivery This role will work as part of a collaborative team assisting our top customers with: Contextualizing and prioritizing findings to put together a comprehensive account and briefing of the events that transpired during a security incident. Pulling together multiple disparate events to build and communicate a cohesive timeline of activity. Collaborating with stakeholders at every level of the business, including legal, compliance, cybersecurity, engineering, and executive functions. Communicating key objectives and results with clarity and context. Managing all the complexities of large-scale cybersecurity investigations for global multi-national organizations, serving as the primary point of contact. Developing presentations for delivery at internal and external conferences. Lead from the front by ideating, mentoring, and supporting thought leadership efforts across the team. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field o OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection o OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection Citizenship & Citizenship Verification: This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customer and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government Clearance. As stated in the job posting, this position requires verification of United States citizenship due to citizenship-based legal restrictions applicable to the role and as a result, you will need to provide a valid passport, or other approved documents, or verified US government clearance to verify your citizenship. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection o OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection o OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions. Lead and manage high-profile incident response efforts for some of the world's largest businesses. Coordinate and lead all key stakeholders as the primary point of contact for major incidents. (This could include technical teams, executives, consultants, and partners) Identify gaps early in the engagement process and request appropriate resources to fill those gaps. Balance the need for rapid recovery with data collection and evidence preservation. Direct activities to secure Enterprise-scale environments and assess potential data exfiltration or data collection. Management of large-scale incidents in a follow-the-sun format working with fellow team members from across the globe. Contextual application of MITRE Attack Framework and or OSI Model. Delivery of complex and technical discussions effectively to customer representatives of varying levels. Experience working with methods utilized for evidence collection, maintenance of chain of custody and associated documentation, evidence storage and analysis, and evidentiary reporting. Eligibility to obtain or currently active government security clearance. Experience analysing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations. Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability. Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information.

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.

Original authoritative source

JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Apply through JobOpportunity →

Browse current JobOpportunity listings from Microsoft Careers →

Related opportunities

Other current verified records you may want to review.

Job

Software Development Engineer II, Amazon Fulfillment Technologies (AFT) - Workforce Optimization

Amazon Development Centre Canada ULC · Canada

Have you ever ordered a product from Amazon and been amazed by how fast it gets to you? Every day, Amazon engineers are working relentlessly to m...

Job

Software Development Engineer, Platform Matching Systems and Policies (IAPP)

Amazon.com Services LLC · United States

The PRISM (Product Identity and Semantic Matching) team is responsible for establishing product identity and attributes, lighting up the product...

Job

Sr Manager, Ad Programs, Ads Trust

ADCI - Karnataka · India

Role Overview The Senior Manager, AT Quality & Support Operations will define and execute the global vision for Ad moderation and relevance quali...

Job

Technical Business Developer, Prime Video Channels

Amazon.com Services LLC · United States

Drive the strategy for how Prime Video becomes the one place customers go to stream all of their favorite content — movies, TV, sports and news....

Job

Site EHS Manager II

Amazon.com Services LLC · United States

Join Amazon’s mission to become Earth’s safest place to work! At Amazon, we’ve set the ambitious goal to become the benchmark of safety excellenc...

Job

Governance, Risk, and Compliance (GRC) Specialist, AWS Security

Amazon Web Services Australia Pty Ltd · Australia

Applicants must be Australian citizens and hold or be eligible to obtain an Australian Government Security Clearance with the ability to successf...

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books