We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Security Operations Engineer

Microsoft
United States, Washington, Redmond
Jul 28, 2025
OverviewAre you looking for a challenge that puts you at the center of the Microsoft Edge + Platform Security Fundamentals (EPSF) strategy? Are you passionate about solving the security challenges of critical online services? Are you passionate about defensive and offensive security? Microsoft's EPSF (Edge + Platform Security Fundamentals) team is responsible for securing some of Microsoft's largest and most influential online services in the Azure Edge & Platform (AEP) organization and Windows Devices organization (W+D). The EPSF Services Pentest (SERPENT) team needs a Senior Security Operations Engineer to increase our business partners' security posture.
ResponsibilitiesEPSF Security has a world-class security team that helps ensure a secure experience for millions of users worldwide. We primarily focus on offensive security and defensive security and work closely with multiple teams across the company to continually improve our operational awareness.The primary responsibilities of this role include:* Monitoring and DetectionIdentifies potential issues with detection (e.g., false positives, noise); engages others to escalate appropriately. Analyzes potential or actual intrusions identified as a result of monitoring activities. Creates detections based on available data (e.g., Indicators of Compromise [IOC] and Tools Tactics Procedures [TTP]). Continues to drive automation of detection and response.* Translate Security Policy and Standards into Effective ControlsImplements security policy and standards for the service; escalates issues and recommends mitigations accordingly. Identifies gaps in security policy and administration and recommends mitigation strategies. Engages with other teams to drive consistency and awareness of security policies and standards. Educates others (e.g., business partners, peers) on security policy.* CollaborationWith minimal guidance, works with internal and external parties to push solutions to the environment to address threats.* Data-Driven AnalysisAnalyzes key metrics and key performance indicators (KPIs) and other data sources (e.g., bugs, unhealthy data pipeline) and identifies trends in security issues and escalates appropriately. Recommends improvements and/or metrics to address gaps in measurement. Leverages multiple sources of data in conducting and interpreting analysis. Evaluates data sets for anomalies and other patterns.* Penetration TestingDrives processes across kill chain; evaluates tactics for effectiveness and to inform security posture. Organizes and contributes to Red Team reports and issue tracking.* AutomationIdentifies and raises opportunities for automation to improve efficiency and effectiveness. Creates automation as appropriate to drive greater efficiency with high value.* Identification and Detection of Control FailuresProactively identifies and investigates potential issues in controls (e.g., network, identity, high security); leverages expertise and team members to address and drive down issues accordingly. Identifies and/or recognizes patterns and recommends potential mitigation strategies. Finds opportunities to leverage and contribute to the internal Microsoft community.* Security Incident ResponseWith minimal guidance, analyzes attempted or successful efforts to compromise systems security; identifies potential next steps to resolve. Works with partner teams on recommendations to limit exposure. Implements appropriate response plans. Continues to develop ability to analyze independently and make recommendations; influences others to take action.* Threat Intelligence and Analysis* Identifies potential threats based on external trends and recommends prioritization for defense-building capabilities.
Applied = 0

(web-6886664d94-nm6rc)