Cyber Defense Operations Hub and Incident Command Leader

Redmond, Washington, United States

Microsoft

Entdecken Sie Microsoft-Produkte und -Dienste für Ihr Zuhause oder Ihr Unternehmen. Microsoft 365, Copilot, Teams, Xbox, Windows, Azure, Surface und mehr kaufen

View all jobs at Microsoft

Apply now Apply later

Security is the foremost concern for Microsoft and our customers in a world increasingly challenged by digital threats, regulatory demands, and estate complexity. The Microsoft Security organization accelerates Microsoft’s mission to ensure that our company and industry effectively secure digital technology platforms, devices, and clouds across our customers’ diverse environments, as well as our own internal systems. Within Microsoft Security, the CISO organization is dedicated to defending the Microsoft estate and protecting our customers and partners who rely on it with our approach reinforced by the Microsoft Secure Future Initiative (SFI), a company wide effort to evolve how we design, build, test, and operate our products and services to achieve the highest possible standards for security. Our strategy is anchored in stopping adversaries through the integration of advanced threat intelligence, proactive threat hunting, rock solid operations, sustainable governance, and the facilitation of automation and augmentation with AI to anticipate, detect, and neutralize even the most sophisticated attacks. We cultivate a culture focused on growth, excellence, and empowering our teams and leaders to perform at their highest level, leading to innovations that impact billions of lives around the world.  

 

We are seeking an experienced Cyber Defense Operations Hub and Incident Command Leader to oversee and enhance the Operations Hub within Microsoft’s Cyber Defense Operations. The Operations Hub is the centerpiece of the Defense Operations organization and is responsible for cybersecurity incident coordination, cross-organizational communications, oversight and monitoring across Defense Operations, and continuous improvement of Defense Operations processes. 

 

With the continued evolution of the external threat landscape, Microsoft continues to be a prime target for a variety of threat actors and experiences an increasing number of attempts to breach its defenses. In this role, you will lead our Operations Hub function within the Cyber Defense Operations team. You will be ensuring the function is coordinating incidents effectively, managing the coordination of incident response activities so they move at pace with clear milestones defined, tracked, and communicated accurately. 

 

In this role, you will also shape the broader framework to monitor and oversee the health and effectiveness of the broader Defense Operations ecosystem, helping to build scalable processes to monitor that cases and incidents are being handled in a timely manner with clear ownership and resolution and to drive continuous improvement to ensure our Cyber Defense Operation function remains agile, efficient, and at the cutting edge of threats and challenges.

 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. 

  

Responsibilities

  • Lead the operational and governance unit to optimize Incident Coordination and Communication capabilities across Microsoft’s Cyber Defense Operations.  
  • Centralize and standardize governance to ensure streamlined, consistent processes to ensure the health and productivity of the Defense Operations ecosystem. 
  • Develop and implement standardized procedures for coordinating large-scale adversary cybersecurity. 
  • Enable continuous monitoring, analysis, and enhancement of cases and incidents across Defense Operations improve operational measures and response capabilities.  
  • Collaborate with cross-functional teams to ensure that incident coordination and communication processes are scalable, efficient, and aligned with organizational goals.  
  • Build strong partnerships across defense, engineering, governance, compliance and security teams to enable timely incident coordination. 
  • Establish metrics and reporting to measure the effectiveness of incident coordination, identifying and addressing gaps or inefficiencies.  
  • Establish metrics and reporting to measure the effectiveness of case handling and resolution across the Defense Operations organization. 
  • Drive process improvements, best practices, and automation opportunities to enhance the methods by which incidents are coordinated and related information is communicated across the organization. 
  • Ensure alignment with broader cybersecurity strategies, compliance requirements, and industry standards.  

  

Qualifications

Required Skills:  

  • 7+ years of experience in cybersecurity, IT operations, or governance roles with a focus on cybersecurity incident response or crisis management processes.  
    • OR Master's Degree in Statistics, Mathematics, Computer Science or related field.
  • 3+ years people management experience.
  • Required understanding of the incident response lifecycle, including the processes and technologies that assist with incident response AND experience working in high scale, cloud architecture environments
  • Ability to design and implement operational processes and standards along with analytical skills with the ability to synthesize multiple and complex threads and provide actionable directions to other team members. 
  • Required communication and collaboration skills to drive alignment across multiple teams and stakeholders and to keep executives informed and aware of important topics. 

 

Other Requirements:

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

  • This position requires verification of citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified with a valid passport. 

Preferred Skills:  

  • Bachelor's degree or more advanced degree in information technology, cybersecurity, or a related field.  
  • Experience with incident response or crisis management disciplines.  
  • Familiarity with Microsoft technologies and security frameworks.  
  • Experience in a large-scale enterprise environment with cross-functional teams.  
  • Experience distilling complex technical concepts into business-oriented outputs for executive consumption and understanding. 

Security Operations Engineering M5 - The typical base pay range for this role across the U.S. is USD $137,600 - $267,000 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $180,400 - $294,000 per year.

 

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here: https://careers.microsoft.com/us/en/us-corporate-pay

      

  • Microsoft will accept applications for the role until Jan 13th, 2025.

 

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.  We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.

 

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.

 

#MSFTSECURITY

Apply now Apply later
Job stats:  0  0  0

Tags: Agile Automation CISO Cloud Compliance Computer Science Cyber defense Governance Government agency Incident response Mathematics Monitoring Strategy Threat intelligence

Perks/benefits: Health care Medical leave Startup environment

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.