Security Operations Engineer
Core
Lead security incident investigations, monitor threats, and automate response workflows for Microsoft's global cloud infrastructure and datacenters.
Role type
Senior IC Security Operations Engineer (Cloud/Incident Response)
Builds
Cyber defense capabilities, automated response playbooks, and threat detection rules for Microsoft Azure and hybrid environments.
Domain
Cloud Security / Cyber Defense / Industrial Network Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response lifecycle, SIEM/EDR/SOAR operations, threat hunting, automation scripting (PowerShell/Python/KQL), network security, large-scale cloud environment security
Preferred skills
OT/critical infrastructure security experience, multi-language automation, advanced security certifications
Technologies
Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, Elastic, Azure Functions, Logic Apps, PowerShell, Python, KQL
Responsibilities
Lead high-severity security incident investigations across cloud and on-premises environments; Monitor, investigate, and respond to security alerts using SIEM and EDR tools; Design and implement SOAR workflows and response automation; Create and tune detection rules and analytics using threat intelligence; Coordinate with engineering and partner teams on incident response activities.
Seniority
Mid-Senior, hands-on IC
