MNC InsiderMNC Insider
Microsoft logo

Security Operations Engineer

Microsoft

Security Operations Engineer

full-timePosted: Aug 18, 2026Updated: Aug 27, 2026Sydney, NSW, AU

Job Description

OverviewIn alignment with our Microsoft values, we are committed to cultivating an inclusive work environment for all employees to positively impact our culture every day and we need you as a Security Operations Engineer. Microsoft’s Cloud Operations & Innovation (CO+I) is the engine that powers our cloud services. As a Security Engineer you will perform a key role in delivering the core infrastructure and foundational technologies for Microsoft's online services including Bing, Office 365, Xbox, OneDrive, and the Microsoft Azure platform. You will implement and operate modern cloud and on premises cybersecurity controls to defend Microsoft datacenter critical infrastructure from threat actors. Leveraging multiple solutions and partnering with internal and external teams, you will be at the forefront of advancing industrial network cybersecurity capabilities. Through on the job learning and bi-directional mentorship, this opportunity will allow you to gain cyber defense, automation, and networking skills and experiences that are rare in both networking and security organizations, and in high demand across multiple industries. This is a flexible work opportunity for you to work from home partially or fully if desired. As a group, CO+I is focused on personal and professional development for all employees and offers trainings and growth opportunities including Career Rotation Programs, Diversity & Inclusion trainings and events, and professional certifications. Our infrastructure is comprised of a large global portfolio of more than 100 datacenters and 1 million servers. Our foundation is built upon and managed by a team of subject matter experts working to support services for more than 1 billion customers and 20 million businesses in over 90 countries worldwide. With environmental sustainability and optimization at the forefront of our datacenter design and operations, we continue to grow and evolve as we meet the ever-changing business demands that hold Microsoft as a world-class cloud provider. Do you want to empower billions across the world? Come and join us in CO+I and be at the forefront of the action! ResponsibilitiesResponsibilities: Incident Response Cyber DefenseLead and participate in security incident investigations across cloud, on-premises, and hybrid environments, including high-severity events and major incidents.Coordinate investigation and reponse activites with engineering, platrom, indentity, network, application and other partner teams.Develop and maintain incident response playbooks, procedures and operational runbooks.Improve Cyber Defense capabilities through process optimization, automation, lessons learned and recommendations that reduce security exposure.Threat Detection & Security OperationsMonitor, investigate and respond to security alerts using Microsoft Sentinel, Microsoft Defender XDR and other SIEM, EDR, and NDR technologies.Analyze attempted and successful compromises, perform proactive threat hunting and develop response and mitigation recommendations with partner teams.Create and tune detection rules, analytics, correlation logic and threat detection content usinf threat intelligence, indicators of compromise and adversary tactics, techniques and procedures.Use operational metrics and security data to improve detection fidelity, response times, service health and customer and partner experience, escalating gaps and recommending improvements as appropriate.Participate in an on-call rotation supporting security services and incident response.Security Automation & EngineeringDesign and implement SOAR workflows, response automation, and operational tooling using PowerShell, Python, KQL, Logic Apps, Azure Functions, or equivalent technologies. Integrate security technologies and telemetry sources into security operations platforms to reduce analyst effort and improve investigation and response outcomes. Identify gaps and recurring issues in security controls, policies, and operational processes, then work with partner teams to implement consistent, scalable, and automated improvements. Other Embody our culture and values. QualificationsRequired Qualifications: 3+ years of experience in cybersecurity, Security Operations Center operations, incident response, Cyber Defense, Blue Team functions, large-scale computing, software development, or a related technical field; or A bachelor’s degree in computer science, Cybersecurity, Information Technology, Engineering, or a related field, or equivalent experience. Experience investigating security incidents such as malware, credential compromise, unauthorized access, insider threats, or related malicious activity. Knowledge of the incident response lifecycle, security monitoring, threat detection, and SIEM, EDR, or SOAR technologies. Experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, Elastic, or comparable security platforms. Hands-on experience with at least one scripting or security query language, such as KQL, PowerShell, or Python. Understanding of network security and experience securing large-scale cloud environments, preferably Microsoft Azure. Background Check Requirements: Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.While not required, we also look for the following Preferred Qualifications:CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, PCCSE, PCNSE, PCSAE, CCNP Security, CCIE Security and/or Security+ certification.Any experience conducting investigations involving OT, manufacturing, critical infrasructure, energy or industrial enviroments is highly preferred (not mandatory)Experience securing large-scale Microsoft Azure environmentsHands-on experience with multiple scripting or automation languages. This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Locations

  • Sydney, NSW, AU
  • Melbourne, VIC, AU

Skills Required

  • cybersecurityintermediate
  • incident response lifecycleintermediate
  • Microsoft Sentinelintermediate
  • at least one scriptingintermediate
  • multiple scriptingintermediate

Required Qualifications

  • 3+ years of experience in cybersecurity, Security Operations Center operations, incident response, Cyber Defense, Blue Team functions, large-scale computing, software development, or a related technical field; (experience, 3 years)
  • 3+ years of experience in cybersecurity, Security Operations Center operations, incident response, Cyber Defense, Blue Team functions, large-scale computing, software development, or a related technical field; (experience, 3 years)
  • or A bachelor’s degree in computer science, Cybersecurity, Information Technology, Engineering, or a related field, or equivalent experience. (experience)
  • or A bachelor’s degree in computer science, Cybersecurity, Information Technology, Engineering, or a related field, or equivalent experience. (experience)
  • Experience investigating security incidents such as malware, credential compromise, unauthorized access, insider threats, or related malicious activity. (experience)
  • Knowledge of the incident response lifecycle, security monitoring, threat detection, and SIEM, EDR, or SOAR technologies. (experience)
  • Experience investigating security incidents such as malware, credential compromise, unauthorized access, insider threats, or related malicious activity. (experience)
  • Knowledge of the incident response lifecycle, security monitoring, threat detection, and SIEM, EDR, or SOAR technologies. (experience)
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, Elastic, or comparable security platforms. (experience)
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, Elastic, or comparable security platforms. (experience)
  • Hands-on experience with at least one scripting or security query language, such as KQL, PowerShell, or Python. (experience)
  • Hands-on experience with at least one scripting or security query language, such as KQL, PowerShell, or Python. (experience)
  • Understanding of network security and experience securing large-scale cloud environments, preferably Microsoft Azure. (experience)
  • Understanding of network security and experience securing large-scale cloud environments, preferably Microsoft Azure. (experience)
  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: (experience)
  • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter. (experience)
  • While not required, we also look for the following Preferred Qualifications: (experience)
  • CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, PCCSE, PCNSE, PCSAE, CCNP Security, CCIE Security and/or Security+ certification. (certification)
  • Any experience conducting investigations involving OT, manufacturing, critical infrasructure, energy or industrial enviroments is highly preferred (not mandatory) (experience)
  • Experience securing large-scale Microsoft Azure environments (experience)
  • Hands-on experience with multiple scripting or automation languages. (experience)
  • This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. (experience)

Responsibilities

  • Lead and participate in security incident investigations across cloud, on-premises, and hybrid environments, including high-severity events and major incidents.
  • Coordinate investigation and reponse activites with engineering, platrom, indentity, network, application and other partner teams.
  • Develop and maintain incident response playbooks, procedures and operational runbooks.
  • Improve Cyber Defense capabilities through process optimization, automation, lessons learned and recommendations that reduce security exposure.
  • Monitor, investigate and respond to security alerts using Microsoft Sentinel, Microsoft Defender XDR and other SIEM, EDR, and NDR technologies.
  • Analyze attempted and successful compromises, perform proactive threat hunting and develop response and mitigation recommendations with partner teams.
  • Create and tune detection rules, analytics, correlation logic and threat detection content usinf threat intelligence, indicators of compromise and adversary tactics, techniques and procedures.
  • Use operational metrics and security data to improve detection fidelity, response times, service health and customer and partner experience, escalating gaps and recommending improvements as appropriate.
  • Participate in an on-call rotation supporting security services and incident response.
  • Design and implement SOAR workflows, response automation, and operational tooling using PowerShell, Python, KQL, Logic Apps, Azure Functions, or equivalent technologies.
  • Integrate security technologies and telemetry sources into security operations platforms to reduce analyst effort and improve investigation and response outcomes.
  • Identify gaps and recurring issues in security controls, policies, and operational processes, then work with partner teams to implement consistent, scalable, and automated improvements.
  • Embody our culture and values.
  • Embody our culture and values.

Benefits

  • general: Flexibility: Balance what matters—your work, your life, and your team—through trust, autonomy, and shared accountability
  • general: Growth: Stretch your skills, expand your impact, and grow with support that meets you where you are
  • general: Wellbeing: Support for your body, mind, and financial future—so you can stay energized and do your best work
  • general: Community PCS: Find your people, build your network, and feel supported every step of the way

Travel Requirements

Less than 25%

Target Your Resume for "Security Operations Engineer" , Microsoft

Get personalized recommendations to optimize your resume specifically for Security Operations Engineer. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Security Operations Engineer" , Microsoft

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

Security Operations EngineeringSecurity EngineeringSecurity Operations EngineeringSecurity Engineering

Answer 10 quick questions to check your fit for Security Operations Engineer @ Microsoft.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.