Overview
Lead SecOps discovery workshops, capture current-state SOC maturity, map detection, response, escalation, and operational gaps, and translate findings into pragmatic modernization roadmaps. Develop KQL hunting logic, incident triage workflows, response playbooks, and reusable delivery assets that reduce manual effort and improve analyst productivity. Apply agentic SOC patterns using SOCBot / Autonomous SOC concepts, with clear human-in-the-loop approval, read/write separation, auditability, and safe automation guardrails. Partner with security architects, customer SOC leaders, product groups, and engineering teams to resolve delivery risks, validate design choices, and drive customer outcomes. Support pre-sales and solution shaping through effort estimation, technical assumptions, discovery questions, solution narratives, and customer-facing demos. Technical Depth Expected- SecOps delive
Full job description
Full Job Description
Lead SecOps discovery workshops, capture current-state SOC maturity, map detection, response, escalation, and operational gaps, and translate findings into pragmatic modernization roadmaps. Develop KQL hunting logic, incident triage workflows, response playbooks, and reusable delivery assets that reduce manual effort and improve analyst productivity. Apply agentic SOC patterns using SOCBot / Autonomous SOC concepts, with clear human-in-the-loop approval, read/write separation, auditability, and safe automation guardrails. Partner with security architects, customer SOC leaders, product groups, and engineering teams to resolve delivery risks, validate design choices, and drive customer outcomes. Support pre-sales and solution shaping through effort estimation, technical assumptions, discovery questions, solution narratives, and customer-facing demos. Technical Depth Expected- SecOps delivery Automation and AI Security Copilot usage, Azure AI Foundry awareness, Logic Apps, Azure Functions, PowerShell, KQL, APIs, managed identities, OAuth / OBO concepts, and automation safety controls. Consulting and Delivery Executive communication, discovery facilitation, architecture documentation, risk-based prioritization, stakeholder management, quality delivery, and reusable IP contribution. 5+ years of experience in cybersecurity consulting, security operations, SOC engineering, incident response, SIEM/SOAR, or related security delivery roles. Strong understanding of detection engineering, incident triage, threat hunting, investigation lifecycle, containment / remediation options, and SOC governance. Ability to produce high-quality customer-facing deliverables such as architecture documents, discovery outputs, deployment plans, design decisions, risk registers, and operational runbooks. Experience communicating complex security concepts to technical teams, program stakeholders, and executive audiences. Degree or equivalent experience in Computer Science, Engineering, Information Security, Cybersecurity, or a related discipline. Ability to identify repeatable delivery IP opportunities and convert project learnings into reusable accelerators, templates, workshops, and enablement materials. Comfortable working across multi-cloud and hybrid customer environments, including ITSM, CMDB, ticketing, threat intelligence, and vulnerability management integrations. Growth mindset to continuously learn EAG Security agent portfolio capabilities and position them in customer conversations and delivery engagements.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Microsoft Careers →