Senior Security Site Reliability Engineer

Senior Security Site Reliability Engineer

Senior Security Site Reliability Engineer

Job Overview

Location
London, England
Job Type
Full Time Job
Job ID
37304
Date Posted
1 year ago
Recruiter
John Apl
Job Views
56

Job Description

Do you have a passion for security and excitement about impacting some of the largest and most complex security challenges Microsoft is involved with to protect petabytes of business-critical customer data? We are looking for a Security Response Team (SRT) Investigator with the right mix of technical depth, engineering background, on-line services experience, and collaboration skills to help grow and protect Office 365 cloud services. 

 

Microsoft 365 is at the center of Microsoft’s cloud first, devices first strategy bringing together cloud-hosted offerings of our most trusted communications and collaboration services (like Exchange, SharePoint, Teams, and more!) with our cross-platform desktop and mobile clients.

 

As a Senior Security Site Reliability Engineer, you will work closely with other cloud and security experts across Microsoft to investigate threats, proactively hunt for compromise, automate capabilities, develop security tooling and data automation, and contribute your experience and expertise to countless other projects.   We work in DevOps model within the Security business and need someone who has a passion for automating their way our of having to do the same thing twice and always thinking about how to scale what we do to millions and millions of users, hosts, and operations. You will be working to solve issues related to the latest security trends and early warning indicators, as well as help design solutions for emerging threats. M365 Security is a fast-paced team that constantly provides new opportunities to learn and grow. 

Responsibilities

Plan and execute proactive adversary hunt for malicious activity using myriad log sources, network- and host-based tools, and threat intelligence to identify the threat actors and their tools and techniques.

Participate in- and contribute to- cyber threat intelligence sharing forums and platforms; organize and curate threat intelligence; form macroscopic perspective on adversaries, actors, and campaigns.

Perform investigation on suspected compromised assets and services, and analyze log data and other artifacts to determine what occurred.

Analyze and improve situational awareness, monitoring coverage, and incident response capabilities.

Design, develop, debug, and deliver tooling to assist the investigative and hunting process.

Collect, curate, and transform various data to support advanced analytic creation and investigation automation.

Create technical documentation for other analysts and other teams to follow.

Work with other internal and external teams to forge new and improve existing partnerships that help mature the teams' techniques, tactics, and procedures (TTPs).

Qualifications

Required Qualifications

Microsoft Cloud Background Check: The successful candidate must pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.

4+ years working in cyber security (Information Security, InfoSec, SecOps, Security Operations, SOC, CSOC, analyst, researcher, etc.).

Deep understanding of adversary and cyber intel frameworks such as kill-chain model, ATT&CK framework, and Diamond Model.

Experience with big data and SIEM solutions such as ArcSight, Splunk, ElasticSearch, Logstash, Azure Data Explorer, Azure Log Analytics, Azure Data Lake, or Azure Sentinel.

Skilled working with extremely large data sets to answer complex and ambiguous questions, using tools and languages like: SQL, KQL, Jupyter Notebook, Spark, Azure Synapse, R, U-SQL, Python, Splunk, and PowerBI.

Previous experience performing development and code debugging with functional or object-oriented programming such as .NET or Java.

Demonstrate ability to understand and communicate technical details with varying levels of management.

Expectation to learn new tools and techniques every day.

 

Preferred Qualifications

An exceptionally well-qualified candidate will meet one or more of the following criteria:

Bachelor's degree in related discipline such as computer security, computer science, computer engineering or information technology.

Good working knowledge of common security, encryption, and protocols such as encryption, PKI, modern authentication and cloud app authorization architectures and protocols such as SAML or OAUTH.

Past experience working in large scale enterprise products: M365 products such as Exchange, SharePoint, Skype, Teams.

Deep and practical OS security/internals knowledge for Linux and Windows.

Exposure to security related subjects and trends such as digital forensics, reverse engineering, penetration testing, and malware analysis.

Ability to rapidly automate data handling and data curation using PowerShell, Python, Azure Data Factory, and various Azure-based tools.

Hands-on experience building Azure-based services with Azure Resource Manager (ARM), ARM templates, ARM policy, IaaS, VMSS, KeyVault, EventHub, Azure Active Directory (AAD), etc.

Hands-on experience with Continuous Integration/Continuous Delivery (CI/CD), Azure DevOps and Agile Scrum.

Ability to work effectively in ambiguous situations and respond favorably to change.

Comfortable working in a startup mode on a new team where there is lots of opportunity.

Certifications like GCIA, GSLC, GCIH, CISM, CISSP, CEH, Etc. are plus.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.  We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request via the Accommodation request form.

Job ID: 37304

Similar Jobs

Cargill

Full Time Job

Senior security site reliability engineer Senior security site reliability engineer

A Typical Work Day May Include: • Completing preventative, predictive, ...

Full Time Job

Deloitte

Full Time Job

Senior security site reliability engineer Senior security site reliability engineer

Are you looking to elevate your cyber career? Your technical skills? Your opport...

Full Time Job

Cargill

Full Time Job

Senior security site reliability engineer Senior security site reliability engineer

Cargill Animal Nutrition is a global business that serves large-scale feed mill ...

Full Time Job

Veolia

Full Time Job

Senior security site reliability engineer Senior security site reliability engineer

Primary Duties / Responsibilities:● Assist in daily operational troublesho...

Full Time Job

Cookies

This website uses cookies to ensure you get the best experience on our website.

Accept