Back to Remote jobs  >   AI / ML
Incident Response Engineer @Microsoft
AI / ML
Salary unspecified
Remote Location
remote UK
Job Type full-time
Posted YDay

[Hiring] Incident Response Engineer @Microsoft

YDay - Microsoft is hiring a remote Incident Response Engineer. 💸 Salary: unspecified 📍Location: UK

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

Interested in security and incident response? Then come join the Cybersecurity Incident Response Team (CIRT) at Microsoft as an Incident Response Engineer responsible for helping customers investigate security incidents in their environment.

As an Incident Response engineer, you will be an elite member of a customer facing security support team leading incident response investigations for Microsoft’s enterprise customers. You have experience in analysing, triaging, scoping, containing, providing guidance for remediation, and determining the root cause of security incidents. You are familiar with collecting and analysing security incident related data to identify indicators of attack and compromise.

This role is flexible in that you can work up to 100% from home.

In the Customer Service & Support (CSS) team we are looking for people with a passion for delivering customer success. As an Incident Response Engineer, you will own, troubleshoot, and solve complex customer technical issues. This opportunity will allow you to accelerate your career growth, hone your problem-solving, collaboration and research skills, and deepen your technical proficiency.

Responsibilities

  • Scope customer security incidents.
  • Understand and identify indicators of attack and indicators of compromise.
  • Investigate root cause of complex security incidents.
  • Analyse incident data from threat analytics tools.
  • Collaborate with the Security and Threat Intelligence teams by providing indicators of compromise and samples of malware from the customer’s environment.
  • Coordinate a response to the security incident with other Microsoft security and consulting teams.
  • Develop, document, and implement runbooks, capabilities, and techniques for Incident Response.
  • Perform security triage and analysis on endpoint, server, and network infrastructure.
  • Perform activities necessary for immediate containment and short-term resolution of incidents.
  • Maintain current knowledge and understanding of the threat landscape, emerging security threats, and vulnerabilities.
  • Maintain a high level of confidentiality.
  • Participate in the on-call rotation as required.

Qualifications

  • Demonstrated experience in customer-facing roles (Customer support experience is preferred).
  • Practical experience managing and troubleshooting Network, Windows Server, Windows Client, and Active Directory environments.
  • Working knowledge of Entra ID and Microsoft 365 management and troubleshooting experience.
  • Experience or passion in Cybersecurity and Security Incident Response.
  • Ability to manage complex Incident Response situations with a focus on deep technical troubleshooting and empathetic customer engagement.
  • Experience supporting large and complex geographically distributed enterprise environments with 1000+ users.
  • Bachelor's degree in Computer Science, Information Technology (IT), or related field AND demonstrated experience of technical support, technical consulting experience, or information technology experience.

Requirements

  • Experience in Security Incident Response with recent operational security experience (Indicator of Attack / Indicator of Compromise deep investigation, On-Premises data and Cloud log investigation, Malware Analysis, Threat Analytics, Threat Intelligence, endpoint security, etc.)
  • Experience in Network Security Administration, and/or Systems Administration with experience in Windows Server, Windows Client, and Active Directory Administration.
  • Experience in Cloud investigations with Entra ID, Microsoft 365 and Microsoft Defender solutions.
  • Experience with any Microsoft Defender solutions.
  • Experience in Azure Identity management and troubleshooting.
  • Kusto Query Language knowledge.
  • Cloud experience with any of the major cloud providers, including cloud security, networking, and migration of multi-cloud or hybrid deployments.
  • Automation (PowerShell and/or Python, Java, or a similar language, can be a beginner to intermediate level).
  • Preferred IT Industry certifications (Microsoft Certifications On-Prem or Cloud, SANS GCIH, CISSP, CEH, Amazon AWS, etc.).
  • Preferred Bachelor’s degree or higher in a technical field, or relevant work experience.

Language Qualification

  • English Language: fluent in reading, writing and speaking.
Before You Apply
remote Be aware of the location restriction for this remote position: UK
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs  >   AI / ML
Incident Response Engineer @Microsoft
AI / ML
Salary unspecified
Remote Location
remote UK
Job Type full-time
Posted YDay
Apply for this position Unlock 85,418 Remote Jobs
remote Be aware of the location restriction for this remote position: UK
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position Unlock 85,418 Remote Jobs
×
  • Unlock 85,418 hidden remote jobs.
  • Your shortcut to remote work. Apply before everyone else.
  • Click and apply. No middlemen, no hassle.
  • Filter by location/skills/salary…
  • Create custom email alerts
Unlock All Jobs Now