Security Operations Engineer

Microsoft Microsoft · Big Tech · Redmond, WA +2 · Security Operations Engineering

This role focuses on security operations and identity and access management (IAM) within Microsoft's Cloud & AI organization. The engineer will ensure secure access, drive identity lifecycle management, and enable automation using tools like PowerShell and Power Automate, with an emphasis on integrating AI-powered workflows. While AI is mentioned as a tool for automation, the core function is security operations and IAM engineering, not building AI models themselves.

What you'd actually do

  1. Oversee identity governance for Exchange Online, guest lifecycle, and Azure Virtual Desktop while maintaining strict security standards.
  2. Administer and troubleshoot Active Directory and Azure AD, including authentication flows, GPOs, OUs, and secure access provisioning.
  3. Develop PowerShell scripts, build workflows with Power Automate/Apps, and integrate ServiceNow/IcM for operational efficiency.
  4. Enable automation using AI powered workflows.

Skills

Required

  • Active Directory
  • Azure AD
  • PowerShell
  • identity governance
  • security operations
  • threat modeling
  • anomaly detection
  • SIEM
  • IT operations incident response

Nice to have

  • Windows/Azure Virtual Desktop
  • Microsoft Entra ID (Azure AD)
  • Microsoft Power Platform
  • Power BI
  • incident management ticketing systems
  • ServiceNow
  • IcM

What the JD emphasized

  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 1+ year(s) experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
  • Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 2+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
  • equivalent experience
  • Microsoft Cloud Background Check