Senior Security Investigator - Ctj - Poly

Microsoft Microsoft · Big Tech · Redmond, WA +4 · Security Operations Engineering

Senior Security Investigator role focused on investigating threats, proactive threat hunting, automating security capabilities, and developing security tooling for Microsoft 365 cloud services. Requires expertise in analyzing large datasets, identifying security issues, and recommending improvements.

What you'd actually do

  1. Skilled working with extremely large data sets to answer complex and ambiguous questions, using tools and languages like: SQL, KQL, Jupyter Notebook, Spark, Azure Synapse, R, U-SQL, Python, Splunk, and Power BI.
  2. Perform investigation on suspected vulnerable or compromised assets and services, and analyze log data and other artifacts to determine what occurred.
  3. Identify potential issues with detection (e.g., false positives, noise). Analyze potential or actual intrusions identified as a result of monitoring activities. Create detections based on available data (e.g., Indicators of Compromise [IOC] and Tools Tactics Procedures [TTP]). Continue to drive automation of detection and response.
  4. Plan and execute proactive adversary hunt for malicious activity using myriad log sources, network- and host-based tools, and threat intelligence to identify the threat actors and their tools and techniques.
  5. Analyze key metrics and key performance indicators (KPIs) and other data sources (e.g., bugs, unhealthy data pipeline) and identifies trends in security issues and escalates appropriately. Recommend improvements and/or metrics to address gaps in measurement.

Skills

Required

  • SQL
  • KQL
  • Jupyter Notebook
  • Spark
  • Azure Synapse
  • R
  • U-SQL
  • Python
  • Splunk
  • Power BI
  • threat modeling
  • anomaly detection
  • Security Operations Center (SOC) detection
  • threat analytics
  • security incident and event management (SIEM)
  • operations incident response
  • Doctorate in Statistics, Mathematics, Computer Science, Cyber Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Cyber Security, or related field AND 3+ years experience OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Cyber Security, or related field AND 4+ years experience OR equivalent experience
  • U.S. Government Top Secret Clearance with access to Sensitive Compartmented Information (SCI) based on a Single Scope Background Investigation (SSBI) with Polygraph

Nice to have

  • DevOps model
  • engineering background
  • on-line services experience
  • collaboration skills

What the JD emphasized

  • extremely large data sets
  • automation
  • security challenges
  • customer data
  • threat hunting
  • security tooling
  • security trends
  • emerging threats
  • security issues
  • security clearance
  • U.S. Government Top Secret Clearance
  • Sensitive Compartmented Information (SCI)
  • Single Scope Background Investigation (SSBI) with Polygraph