Principal Security Operations Engineer

Reposted Yesterday
Be an Early Applicant
Redmond, WA, USA
In-Office
143K-304K Annually
Expert/Leader
Software • Quantum Computing • Metaverse • Infrastructure as a Service (IaaS)
The Role
Own end-to-end cybersecurity, insider threat, and external threat incident response for Microsoft Quantum, including detection, investigation, containment, recovery, root-cause analysis, and executive closure. Lead cross-functional response with security, legal, HR, trade, and national security teams. Define the architecture and operating model for an AI-enabled SOC, improve Microsoft Sentinel detections and data onboarding, and translate incident findings into durable controls, runbooks, and monitoring improvements.
Summary Generated by Built In
Overview

Quantum computing has the potential to massively accelerate science and technology innovation. Microsoft Discovery & Quantum is building advanced computing platforms, spanning HPC, AI, and quantum, to realize that future. You will join the Quantum Security & IT Operations (QSIT) team protecting a globally distributed research community and its intellectual property. 

As a Principal Security Operations Engineer in QSIT, you will own the response to cybersecurity, external & insider threat incidents affecting Microsoft Quantum, from initial detection and severity assessment through containment, recovery, root-cause analysis, and executive closure working across National Security Team, HR, Legal, Global Trade, and CISO organizations. You will set the technical direction for incident handling, coordinate responders across Quantum and Microsoft security organizations, and ensure lessons learned translate into durable improvements to controls, detections, and operating procedures. 

You will also define and drive the requirements for an AI-enabled QSIT Security Operations Center, shaping how AI supports signal enrichment, triage, investigation, response, and analyst decision-making while maintaining strong auditability and data-handling controls.  

This role requires broad technical and risk judgment, independent leadership in ambiguous situations, and the ability to influence security strategy across organizational boundaries. 

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. 

This role is onsite in Redmond, WA. 


Responsibilities
  • Own cybersecurity incidents affecting Microsoft Quantum, establishing severity and response strategy, directing technical investigation and containment, coordinating recovery, and driving incidents to clear, accountable closure. 

  • Manage insider and external threat incident analysis and triage from initial indicators through scoping, forensic review, evidence preservation, case disposition, and root-cause analysis, producing defensible investigative narratives for executive, legal, and compliance review. 

  • Drive changes to systems and processes based on incident and risk learnings that cross and impact other teams.  

  • Lead cross-functional incident response with Quantum engineering, Microsoft CISO organization, National Security Team, HR, Legal, and Global Trade; provide concise executive updates, document decisions and evidence, and ensure post-incident actions are assigned and completed. 

  • Define and drive the requirements, architecture, operating model, and prioritized engineering backlog for an AI-enabled QSIT SOC, covering signal enrichment, triage, investigation, response recommendations, analyst-in-the-loop controls, auditability, and sensitive-data handling. 

  • Translate AI SOC needs into measurable capabilities and acceptance criteria, evaluate first- and third-party solutions, guide implementation, and assess operational effectiveness, risk, and readiness for production use. 

  • Design, implement, and tune insider threat and cybersecurity detections in Microsoft Sentinel and related platforms; onboard and normalize new security data streams; identify visibility gaps; and convert incident findings into improved detections, controls, runbooks, and monitoring coverage. 

    • Embody our Culture and Values 


Qualifications

Required/minimum qualifications

  • Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR equivalent experience.

Other Qualifications

  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
    • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.
  • Citizenship & Citizenship Verification: This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide proof of citizenship, U.S. permanent residency, or other protected status (e.g., under 8 U.S.C. § 1324b(a)(3)) for assessment of eligibility to access the export-controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate's citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.Additional or 

Additional or preferred qualifications

  • Doctorate in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR equivalent experience.
    • CISSP CISA CISM SANS OSCP Security+
  • 6+ years of experience in cybersecurity, security operations, incident response, insider threat, threat analytics, security information and event management (SIEM), or equivalent experience.
  • Demonstrated experience leading complex security incidents end-to-end, including technical investigation, containment, recovery, root-cause analysis, executive communication, and post-incident remediation.
  • Hands-on experience with Microsoft Sentinel (KQL) or an equivalent enterprise SIEM, including detection engineering, data onboarding, investigative analysis, and the ability to set technical direction across ambiguous, high-impact security situations.
  • CISSP certification or other relevant (CISA, CISM, SANS GCIA, GCIH, OSCP, Security+).
  • Experience collaborating with corporate insider threat, investigations, legal, or trade compliance functions; exposure to dedicated insider threat platforms such as Purview, DTEX, Proofpoint ITM, Magnet Axiom, or Forcepoint.
  • Experience designing, deploying, or evaluating agentic AI or LLM-based automation in a security operations context is strongly desired; familiarity with post-quantum cryptography concepts and CNSA 2.0.
  • Experience or interest in the specific challenges of protecting strategic research programs from sustained external targeting; familiarity with export control (EAR / ITAR) and government program environments.

#Quantum #QuantumCareers #MDQCareers  #Security


Security Operations Engineering IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Skills Required

  • Doctorate, master's degree, bachelor's degree, or equivalent experience in Statistics, Mathematics, Computer Science, or a related field
  • At least 3 years of relevant experience with a doctorate, 4 years with a master's degree, or 6 years with a bachelor's degree in software development lifecycle, large-scale computing, threat modeling, cybersecurity, anomaly detection, SOC detection, threat analytics, SIEM, IT, or operations incident response
  • Ability to meet Microsoft Cloud Background Check and other Microsoft, customer, or government security screening requirements
  • Proof of U.S. citizenship, permanent residency, or other protected status for access to export-controlled information
  • CISSP, CISA, CISM, SANS, OSCP, or Security+ certification
  • At least 6 years of experience in cybersecurity, security operations, incident response, insider threat, threat analytics, SIEM, or equivalent
  • Experience leading complex security incidents end to end, including investigation, containment, recovery, root-cause analysis, executive communication, and remediation
  • Hands-on Microsoft Sentinel and KQL or equivalent enterprise SIEM experience, including detection engineering, data onboarding, and investigative analysis
  • Experience collaborating with insider threat, investigations, legal, or trade compliance functions
  • Experience with Purview, DTEX, Proofpoint ITM, Magnet Axiom, or Forcepoint
  • Experience designing, deploying, or evaluating agentic AI or LLM-based security operations automation
  • Familiarity with post-quantum cryptography concepts and CNSA 2.0
  • Experience protecting strategic research programs from sustained external targeting
  • Familiarity with EAR, ITAR, and government program environments

Microsoft Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.

  • Fair & Transparent Compensation Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
  • Retirement Support Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
  • Parental & Family Support Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.

Microsoft Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Redmond, WA
206,870 Employees
Year Founded: 1975

What We Do

At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.

Similar Jobs

Axon Logo Axon

Principal Security Operations Engineer

Artificial Intelligence • Cloud • Social Impact • Software • Wearables
In-Office
5 Locations
2700 Employees
169K-270K Annually

MetLife Logo MetLife

Site Reliability Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
111K-180K Annually

MetLife Logo MetLife

Site Reliability Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
111K-180K Annually

Wells Fargo Logo Wells Fargo

Personal Banker University Place

Fintech • Financial Services
Hybrid
University Place, WA, USA
205000 Employees
23-31 Hourly

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account