Overview
Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers. Technical Delivery This role will work as part of a collaborative team assisting our top customers with: Contextualizing and prioritizing findings to put together a comprehensive account and briefing of the events that transpired during a security incident. Pulling together multiple disparate events to build and communicate a cohesive timeline of activity. Collaborating with stakeholders at every level of the business, including legal,
Full job description
Full Job Description
Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers. Technical Delivery This role will work as part of a collaborative team assisting our top customers with: Contextualizing and prioritizing findings to put together a comprehensive account and briefing of the events that transpired during a security incident. Pulling together multiple disparate events to build and communicate a cohesive timeline of activity. Collaborating with stakeholders at every level of the business, including legal, compliance, cybersecurity, engineering, and executive functions. Communicating key objectives and results with clarity and context. Managing all the complexities of large-scale cybersecurity investigations for global multi-national organizations, serving as the primary point of contact. Developing presentations for delivery at internal and external conferences. Lead from the front by ideating, mentoring, and supporting thought leadership efforts across the team. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field o OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection o OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection Citizenship & Citizenship Verification: This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customer and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government Clearance. As stated in the job posting, this position requires verification of United States citizenship due to citizenship-based legal restrictions applicable to the role and as a result, you will need to provide a valid passport, or other approved documents, or verified US government clearance to verify your citizenship. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection o OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection o OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions. Lead and manage high-profile incident response efforts for some of the world's largest businesses. Coordinate and lead all key stakeholders as the primary point of contact for major incidents. (This could include technical teams, executives, consultants, and partners) Identify gaps early in the engagement process and request appropriate resources to fill those gaps. Balance the need for rapid recovery with data collection and evidence preservation. Direct activities to secure Enterprise-scale environments and assess potential data exfiltration or data collection. Management of large-scale incidents in a follow-the-sun format working with fellow team members from across the globe. Contextual application of MITRE Attack Framework and or OSI Model. Delivery of complex and technical discussions effectively to customer representatives of varying levels. Experience working with methods utilized for evidence collection, maintenance of chain of custody and associated documentation, evidence storage and analysis, and evidentiary reporting. Eligibility to obtain or currently active government security clearance. Experience analysing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations. Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability. Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Microsoft Careers →