Overview
Implement AI-enabled SOC automation and investigation capabilities, including signal enrichment, workflow orchestration, and analyst tooling. Develop and operate the security tooling, data integrations, dashboards, and supporting platforms required for reliable day-to-day security operations. Tune detections and investigation workflows to improve signal quality, reduce false positives, shorten investigation time, and increase analyst productivity. Participate in incident investigation and response, maintain operational readiness, and troubleshoot security issues affecting network, infrastructure, and physical security services. Partner with engineering, facilities, networking, and security teams to automate manual processes, resolve operational issues, and strengthen end-to-end resilience. Embody our Culture and Values Doctorate in Statistics, Mathematics, Computer Science, or related fi
Full job description
Full Job Description
Implement AI-enabled SOC automation and investigation capabilities, including signal enrichment, workflow orchestration, and analyst tooling. Develop and operate the security tooling, data integrations, dashboards, and supporting platforms required for reliable day-to-day security operations. Tune detections and investigation workflows to improve signal quality, reduce false positives, shorten investigation time, and increase analyst productivity. Participate in incident investigation and response, maintain operational readiness, and troubleshoot security issues affecting network, infrastructure, and physical security services. Partner with engineering, facilities, networking, and security teams to automate manual processes, resolve operational issues, and strengthen end-to-end resilience. Embody our Culture and Values Doctorate in Statistics, Mathematics, Computer Science, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience. CISSP CISA CISM SANS OSCP Security 2+ years of experience programming in C++/C# or Python or Scala or similar technologies. Demonstrated experience coordinating incidents and supporting live services, including investigation, containment, recovery, escalation, triage, root-cause analysis, stakeholder communication, and operational readiness. Hands-on experience with security automation and AI-assisted operational workflows using PowerShell, Python, Logic Apps, or similar technologies for signal enrichment, investigations, workflow orchestration, and decision support. Working knowledge of enterprise networking, including DNS, TCP/IP, firewalls, routing, VPNs, and network troubleshooting. Experience working with SOC, NOC. Experience collaborating with corporate insider threat, investigations, legal, or trade compliance functions; exposure to dedicated insider threat platforms such as Purview, DTEX, Proofpoint ITM, Magnet Axiom, or Forcepoint. Experience designing, deploying, or evaluating agentic AI or LLM-based automation in a security operations context. Experience or interest in the specific challenges of protecting strategic research programs from sustained external targeting; familiarity with export control (EAR / ITAR) and government program environments.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Microsoft Opportunities →