Verified current Job

Security Operations Engineer

Incident Response Cyber Defense Lead and participate in security incident investigations across cloud, on-premises, and hybrid environments, including high-severity events and major incidents. Coordinate investigation and reponse...

Job Full source details
Microsoft Sydney, NSW,AU, AU Source published Aug 18, 2026 Verified 8 hours ago
✓ 95% verification score · Source: Microsoft Careers · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
Security Operations Engineer opportunity at Microsoft
DeadlineSun Feb 14 4:23 AM 2027
EmploymentF U L L T I M E
CountryAU

Overview

Incident Response Cyber Defense Lead and participate in security incident investigations across cloud, on-premises, and hybrid environments, including high-severity events and major incidents. Coordinate investigation and reponse activites with engineering, platrom, indentity, network, application and other partner teams. Develop and maintain incident response playbooks, procedures and operational runbooks. Improve Cyber Defense capabilities through process optimization, automation, lessons learned and recommendations that reduce security exposure. Analyze attempted and successful compromises, perform proactive threat hunting and develop response and mitigation recommendations with partner teams. Participate in an on-call rotation supporting security services and incident response. Design and implement SOAR workflows, response automation, and operational tooling using PowerShell, Python,

Full job description

Full Job Description

Incident Response Cyber Defense Lead and participate in security incident investigations across cloud, on-premises, and hybrid environments, including high-severity events and major incidents. Coordinate investigation and reponse activites with engineering, platrom, indentity, network, application and other partner teams. Develop and maintain incident response playbooks, procedures and operational runbooks. Improve Cyber Defense capabilities through process optimization, automation, lessons learned and recommendations that reduce security exposure. Analyze attempted and successful compromises, perform proactive threat hunting and develop response and mitigation recommendations with partner teams. Participate in an on-call rotation supporting security services and incident response. Design and implement SOAR workflows, response automation, and operational tooling using PowerShell, Python, KQL, Logic Apps, Azure Functions, or equivalent technologies. 3+ years of experience in cybersecurity, Security Operations Center operations, incident response, Cyber Defense, Blue Team functions, large-scale computing, software development, or a related technical field; Experience investigating security incidents such as malware, credential compromise, unauthorized access, insider threats, or related malicious activity. These requirements include, but are not limited to the following specialized security screenings: CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, PCCSE, PCNSE, PCSAE, CCNP Security, CCIE Security and/or Security+ certification. Any experience conducting investigations involving OT, manufacturing, critical infrasructure, energy or industrial enviroments is highly preferred (not mandatory) Hands-on experience with multiple scripting or automation languages.

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.

Original authoritative source

JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Apply through JobOpportunity →

Browse current JobOpportunity listings from Microsoft Careers →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books