CareerPlanGet AI match score →

Network Security Service Engineer

United States, Washington, Redmond💼 Full-time🗓 2026-07-06 → 2026-07-31

Core

Proactively identify and investigate security issues, implement automation for network security controls, and respond to intrusions and escalations to limit system exposure.

Role type

Senior IC network security service engineer (detection engineering & incident response)

Builds

Detections, response runbooks, and automation playbooks for Azure Sentinel and partner XDR signals

Domain

Cyber security, threat analytics, and security operations (SOC)

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

threat modeling, anomaly detection, SIEM administration, incident response, detection engineering, automation development, security policy implementation, metrics analysis, intrusion analysis, MITRE ATT&CK mapping

Preferred skills

SOAR playbook development, false-positive reduction, blameless postmortem facilitation, detection-as-code workflow implementation

Technologies

Azure Sentinel, MITRE ATT&CK, SOAR, XDR

Responsibilities

Build and tune detections using detection-as-code workflows; map coverage to MITRE ATT&CK framework; author and maintain TSGs and response runbooks; partner with SOC during P0/P1 incidents; contribute to blameless postmortems; drive automation playbooks to reduce analyst toil; analyze attempted or successful security compromises; respond to escalations and recommend improvements; participate in on-call rotation for security services

Seniority

Senior, hands-on IC

Rewrite
## About the role - Proactively identify and investigate potential issues and patterns in security controls and drive mitigation strategies, while also implementing automation to improve efficiency and effectiveness across the network. - Install, upgrade, and maintain security hardware, operating system and software. - Identify gaps in security policy and administration, recommend solutions, and implement new and revised security standards, while working with partner teams to drive consistency and awareness. - Maintain standards and drive improvements for our customer and partner experience, responding appropriately to emerging issues and advocating for our customer experience through development and analyzation of key metrics, performance indicators, and other data sources (e.g. bugs, unhealthy data pipeline). - Respond to escalations and recommend improvements as appropriate to address gaps. - Participate in on-call rotation to support security services. - With minimal guidance, analyze attempted or successful efforts to compromise systems security and, alongside partner teams, create recommendations to limit exposure, implement response plans, and take action. - Analyze potential or actual intrusions identified from monitoring activities and create detections based on available data (e.g., Indicators of Compromise [IOC] and Tools Tactics Procedures [TTP]). ## Requirements - Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 1+ year(s) experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response - OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 2+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response - OR equivalent experience. ## Nice to have - These requirements include, but are not limited to the following specialized security screenings: - Doctorate in Statistics, Mathematics, Computer Science, or related field - OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection - OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection - OR equivalent experience. ## What we offer - Build, tune, and maintain detections in Azure Sentinel (and partner XDR signals) using a detection-as-code workflow; map coverage to the MITRE ATT&CK framework across network, cloud, and identity stacks; partner with detection engineering to reduce false-positive rate and improve fidelity of high-confidence alerts. - Author and maintain TSGs and response runbooks for owned detections; partner with the SOC during P0/P1 cybersecurity incidents, contribute to blameless postmortems within SLA, and drive action items to closure — including SOAR / automation playbooks that reduce analyst toil and mean-time-to-triage. ## About us - CISSP CISA CISM SANS OSCP Security+
Sourced via microsoft · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply at Microsoft ↗