CareerPlanGet AI match score →

Security Research Manager

Czech Republic, Prague, Prague💼 Full-time🗓 2026-07-03 → 2026-07-31

Core

Lead Prague operations for customer-facing detection, investigation, threat hunting, and response support for Defender Experts XDR, coaching analysts and driving AI adoption.

Role type

Senior IC security operations manager (threat hunting & response)

Builds

Proactive and reactive threat hunting, investigation, and response outcomes for customer environments

Domain

Cybersecurity operations, threat intelligence, incident response

Deliverable

production ML models | product features | dashboards & analysis | client delivery | infrastructure

Required skills

Security Operations, Threat Intelligence, Cyber Incident Response, Penetration Testing/Red Team, Detection Engineering, People management, Team leadership, Service delivery leadership, Coaching technical teams, Leading customer-facing security operations

Preferred skills

Building/scaling new site or region operations teams, Leveraging generative AI and LLMs for security ops, Sponsoring/building automations with scripting or low-code tools, Knowledge of MITRE ATT&CK and kill-chain model, Threat intelligence curation, DFIR, Offensive security techniques

Technologies

Generative AI, Large Language Models, Copilots, Autonomous agents, Scripting languages, Orchestration platforms, Low-code automation tools, Agent frameworks

Responsibilities

Coach security analysts by defining objectives and removing blockers, Establish and manage local operating rhythm for quality and cross-time-zone handoffs, Partner with research and engineering to improve detections and tooling, Drive adoption of AI-powered tools and agentic workflows, Use metrics to identify systemic improvements and translate into processes or automation, Participate in global security operations model including non-standard hours

Seniority

Senior, hands-on IC with people management

Rewrite
## About the role Lead the Prague CZ operations team responsible for customer-facing detection, investigation, threat hunting, and response support for Defender Experts for XDR. Coach security analysts by defining clear objectives and outcomes, connecting work to customer and business impact, giving timely feedback, removing blockers, and helping employees build durable security operations capability. Care for employees by creating an environment where people feel valued, respected, included, and supported in their wellbeing, career growth, and aspirations. Establish and manage the local operating rhythm for quality, coverage, onboarding, training, case review, escalation, customer readiness, and cross-time-zone handoffs. Ensure the team delivers high-quality proactive and reactive threat hunting, investigation, and response outcomes across customer environments. Partner with threat research, data science, engineering, and global operations teams to improve detections, service quality, tooling, triage workflows, and operational readiness. Drive adoption of AI-powered security tools, copilot, and agentic workflows that accelerate investigations, enrich customer findings, improve analytical efficiency, and reduce repetitive operational burden. Sponsor and operationalize AI agents and automations that assist with case enrichment, investigation summarization, detection validation, quality review, onboarding, reporting, and customer-ready outputs. Use metrics, customer feedback, quality reviews, and operational signals to identify systemic improvements and translate them into durable processes, training, automation, or product feedback. Build a healthy, resilient team culture that supports learning, experimentation, knowledge sharing, and continuous improvement while maintaining high standards for customer impact. Participate in a global security operations model, including potential weekend, holiday, or non-standard business-hour coverage where legally allowed and aligned to local requirements. ## Requirements * Experience in Security Operations, Threat Intelligence, Cyber Incident Response, Penetration Testing/Red Team, Detection Engineering, or related cybersecurity operations roles. * People management, team leadership, service delivery leadership, or demonstrated experience coaching technical teams toward operational outcomes. * Experience leading customer-facing or service-delivery security operations where quality, timeliness, communication, and customer outcomes are critical. * Ability to work from the Prague office at least three (3) days per week. * Ability to support weekend, holiday, and non-standard business-hour coverage where legally allowed and aligned to local labor regulations. ## Nice to have * Experience building, leading, or scaling a new site, shift, region, operations team, or service-delivery capability. * Experience leveraging generative AI, large language models, copilots, autonomous agents, or AI-assisted workflows to improve security operations, threat hunting, incident response, investigations, reporting, quality review, or operational efficiency. * Experience sponsoring or building automations or AI-assisted workflows using scripting languages, orchestration platforms, low-code automation tools, or agent frameworks. * Knowledge of kill-chain model, MITRE ATT&CK framework, modern penetration testing techniques, cloud security, identity security, and operating system internals. * Experience with threat intelligence curation, customer briefings, incident response, DFIR, detection engineering, or offensive security techniques. * Additional advanced technical degrees or cyber security certifications such as CISSP, OSCP, CEH, GIAC, or equivalent experience. ## What we offer * Excellent cross-group collaboration and communication skills, including the ability to influence across operations, research, engineering, and business stakeholders. * Strong ability to use data to tell a story, identify systemic improvement opportunities, and drive clear prioritization.
Sourced via microsoft · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply at Microsoft ↗