At a Glance
- Tasks: Join our Cybersecurity Incident Response Team to tackle real security incidents and protect customers.
- Company: Be part of Microsoft, a global leader in technology and innovation.
- Benefits: Enjoy flexible remote work, competitive salary, and opportunities for professional growth.
- Why this job: Make a difference in cybersecurity while developing your skills in a supportive environment.
- Qualifications: Experience in customer support and a passion for cybersecurity are essential.
- Other info: Join a diverse team that values respect, integrity, and collaboration.
The predicted salary is between 36000 - 60000 £ per year.
Interested in security and incident response? Then come join the Cybersecurity Incident Response Team (CIRT) at Microsoft as an Incident Response Engineer responsible for helping customers investigate security incidents in their environment. As an Incident Response engineer, you will be an elite member of a customer facing security support team leading incident response investigations for Microsoft’s enterprise customers. You have experience in analysing, triaging, scoping, containing, providing guidance for remediation, and determining the root cause of security incidents. You are familiar with collecting and analysing security incident related data to identify indicators of attack and compromise.
In the Customer Service & Support (CSS) team we are looking for people with a passion for delivering customer success. As an Incident Response Engineer, you will own, troubleshoot, and solve complex customer technical issues. This opportunity will allow you to accelerate your career growth, hone your problem-solving, collaboration and research skills, and deepen your technical proficiency. This role is flexible in that you can work up to 100% from home.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities:
- Scope customer security incidents.
- Understand and identify indicators of attack and indicators of compromise.
- Investigate root cause of complex security incidents.
- Analyse incident data from threat analytics tools.
- Collaborate with the Security and Threat Intelligence teams by providing indicators of compromise and samples of malware from the customer’s environment.
- Coordinate a response to the security incident with other Microsoft security and consulting teams.
- Develop, document, and implement runbooks, capabilities, and techniques for Incident Response.
- Perform security triage and analysis on endpoint, server, and network infrastructure.
- Perform activities necessary for immediate containment and short-term resolution of incidents.
- Maintain current knowledge and understanding of the threat landscape, emerging security threats, and vulnerabilities.
- Maintain a high level of confidentiality.
- Participate in the on-call rotation as required.
Required/Minimum Qualifications (RQs/MQs):
- Demonstrated experience in customer-facing roles (Customer support experience is preferred).
- Practical experience managing and troubleshooting Network, Windows Server, Windows Client, and Active Directory environments.
- Working knowledge of Entra ID and Microsoft 365 management and troubleshooting experience.
- Experience or passion in Cybersecurity and Security Incident Response.
- Ability to manage complex Incident Response situations with a focus on deep technical troubleshooting and empathetic customer engagement.
- Experience supporting large and complex geographically distributed enterprise environments with 1000+ users.
- Bachelor's degree in Computer Science, Information Technology (IT), or related field AND demonstrated experience of technical support, technical consulting experience, or information technology experience.
Additional or Preferred Qualifications (PQs):
- Experience in Security Incident Response with recent operational security experience (Indicator of Attack / Indicator of Compromise deep investigation, On-Premises data and Cloud log investigation, Malware Analysis, Threat Analytics, Threat Intelligence, endpoint security, etc.)
- Experience in Network Security Administration, and/or Systems Administration with experience in Windows Server, Windows Client, and Active Directory Administration.
- Experience in Cloud investigations with Entra ID, Microsoft 365 and Microsoft Defender solutions.
- Experience with any Microsoft Defender solutions.
- Experience in Azure Identity management and troubleshooting.
- Kusto Query Language knowledge.
- Cloud experience with any of the major cloud providers, including cloud security, networking, and migration of multi-cloud or hybrid deployments.
- Automation (PowerShell and/or Python, Java, or a similar language, can be a beginner to intermediate level).
- Preferred IT Industry certifications (Microsoft Certifications On-Prem or Cloud, SANS GCIH, CISSP, CEH, Amazon AWS, etc.)
- Preferred Bachelor’s degree or higher in a technical field, or relevant work experience.
Language Qualification:
- English Language: fluent in reading, writing and speaking.
- Ability to meet Microsoft, customer and / or government security screening requirements are required for this role.
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances.
If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Senior Incident Response Engineer in Reading employer: Microsoft Corporation
Contact Detail:
Microsoft Corporation Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Incident Response Engineer in Reading
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, or even local tech events. Connecting with others in the cybersecurity field can lead to job opportunities that aren’t even advertised yet.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your incident response projects or any relevant work. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common incident response scenarios. Practice explaining your thought process and how you’d tackle real-world security incidents. Confidence is key!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Senior Incident Response Engineer in Reading
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Senior Incident Response Engineer role. Highlight your experience in incident response, customer support, and any relevant technical skills that match the job description.
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a perfect fit for the CIRT team at Microsoft.
Showcase Your Technical Skills: Don’t forget to mention your technical proficiencies, especially in areas like Windows Server, Active Directory, and any experience with Microsoft Defender solutions. We want to see your expertise!
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows your enthusiasm for joining our team!
How to prepare for a job interview at Microsoft Corporation
✨Know Your Stuff
Make sure you brush up on your technical knowledge, especially around incident response and cybersecurity. Familiarise yourself with common indicators of attack and compromise, as well as the tools used for threat analytics. This will help you speak confidently about your experience and how it relates to the role.
✨Showcase Your Customer Skills
Since this role involves a lot of customer interaction, be prepared to discuss your previous customer-facing experiences. Think of specific examples where you successfully resolved complex issues or provided exceptional support. Highlighting your empathetic approach can set you apart from other candidates.
✨Prepare for Scenario Questions
Expect to face scenario-based questions that test your problem-solving skills in real-world situations. Practice articulating your thought process when handling security incidents, including how you would scope, triage, and contain an incident. This will demonstrate your analytical skills and ability to think on your feet.
✨Stay Updated on Trends
The cybersecurity landscape is always changing, so make sure you're up-to-date with the latest threats and vulnerabilities. Being able to discuss recent incidents or trends during your interview shows your passion for the field and your commitment to continuous learning, which is crucial for this role.