Responsibilities
- Lead the Prague CZ operations team responsible for customer-facing detection, investigation, threat hunting, and response support for Defender Experts for XDR.
- Model Microsoft culture, values, leadership principles, and high standards for customer obsession, operational rigor, inclusion, accountability, and growth mindset.
- Coach security analysts by defining clear objectives and outcomes, connecting work to customer and business impact, giving timely feedback, removing blockers, and helping employees build durable security operations capability.
- Care for employees by creating an environment where people feel valued, respected, included, and supported in their wellbeing, career growth, and aspirations.
- Establish and manage the local operating rhythm for quality, coverage, onboarding, training, case review, escalation, customer readiness, and cross-time-zone handoffs.
- Ensure the team delivers high-quality proactive and reactive threat hunting, investigation, and response outcomes across customer environments.
- Partner with threat research, data science, engineering, and global operations teams to improve detections, service quality, tooling, triage workflows, and operational readiness.
- Drive adoption of AI-powered security tools, copilot, and agentic workflows that accelerate investigations, enrich customer findings, improve analytical efficiency, and reduce repetitive operational burden.
- Sponsor and operationalize AI agents and automations that assist with case enrichment, investigation summarization, detection validation, quality review, onboarding, reporting, and customer-ready outputs.
- Use metrics, customer feedback, quality reviews, and operational signals to identify systemic improvements and translate them into durable processes, training, automation, or product feedback.
- Build a healthy, resilient team culture that supports learning, experimentation, knowledge sharing, and continuous improvement while maintaining high standards for customer impact.
- Participate in a global security operations model, including potential weekend, holiday, or non-standard business-hour coverage where legally allowed and aligned to local requirements.
Qualifications
- Experience in Security Operations, Threat Intelligence, Cyber Incident Response, Penetration Testing/Red Team, Detection Engineering, or related cybersecurity operations roles.
- People management, team leadership, service delivery leadership, or demonstrated experience coaching technical teams toward operational outcomes.
- Experience leading customer-facing or service-delivery security operations where quality, timeliness, communication, and customer outcomes are critical.
- Experience using security telemetry, large data sets, and investigation tools such as Microsoft Defender XDR / Microsoft 365 Defender, Microsoft Sentinel or equivalent SIEM, KQL, Python, Power BI, or comparable analysis tooling.
- Ability to meet Microsoft, customer, and/or government security screening requirements, including the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.
- Ability to work from the Prague office at least three (3) days per week.
- Ability to support weekend, holiday, and non-standard business-hour coverage where legally allowed and aligned to local labor regulations.
- Demonstrated alignment to Microsoft manager expectations: Model the culture and values, Coach employees and teams toward success, and Care for people, growth, inclusion, and wellbeing.
- Experience building, leading, or scaling a new site, shift, region, operations team, or service-delivery capability preferred.
- Experience leveraging generative AI, large language models, copilots, autonomous agents, or AI-assisted workflows to improve security operations, threat hunting, incident response, investigations, reporting, quality review, or operational efficiency.
- Experience sponsoring or building automations or AI-assisted workflows using scripting languages, orchestration platforms, low-code automation tools, or agent frameworks.
- Knowledge of kill-chain model, MITRE ATT&CK framework, modern penetration testing techniques, cloud security, identity security, and operating system internals.
- Experience with threat intelligence curation, customer briefings, incident response, DFIR, detection engineering, or offensive security techniques.
- Excellent cross-group collaboration and communication skills, including the ability to influence across operations, research, engineering, and business stakeholders.
- Strong ability to use data to tell a story, identify systemic improvement opportunities, and drive clear prioritization.
- Additional advanced technical degrees or cyber security certifications such as CISSP, OSCP, CEH, GIAC, or equivalent experience preferred.
Security Research M5 - The typical base pay range for this role across Czechia is Kč 1,983,000.00 - Kč 3,553,000.00 per year. Certain roles may be eligible for benefits and other compensation.
Find additional benefits and pay information here:
https://careers.microsoft.com/v2/global/en/corporate-pay/czech-republic-corporate-pay.html
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Skills Required
- Experience in security operations, threat intelligence, cyber incident response, penetration testing, red team, detection engineering, or related cybersecurity operations
- People management, team leadership, service delivery leadership, or coaching technical teams toward operational outcomes
- Experience leading customer-facing or service-delivery security operations
- Experience with security telemetry, large data sets, and investigation tools such as Microsoft Defender XDR, Microsoft Sentinel, KQL, Python, Power BI, or comparable tools
- Ability to meet Microsoft, customer, and government security screening requirements, including the Microsoft Cloud Background Check
- Ability to work from the Prague office at least three days per week
- Ability to support weekend, holiday, and non-standard business-hour coverage
- Experience building, leading, or scaling a new site, shift, region, operations team, or service-delivery capability
- Experience using generative AI, large language models, copilots, autonomous agents, or AI-assisted workflows in security operations
- Experience building security operations automations using scripting languages, orchestration platforms, low-code tools, or agent frameworks
- Knowledge of kill-chain models, MITRE ATT&CK, penetration testing, cloud security, identity security, and operating system internals
- Experience with threat intelligence curation, customer briefings, incident response, DFIR, detection engineering, or offensive security
- Excellent cross-group collaboration, communication, and stakeholder influence skills
- Ability to use data to identify systemic improvements and drive prioritization
- Advanced technical degree or cybersecurity certification such as CISSP, OSCP, CEH, or GIAC
Microsoft Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.
-
Fair & Transparent Compensation — Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
-
Retirement Support — Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
-
Parental & Family Support — Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.
Microsoft Insights
What We Do
At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.


%20copy.jpg)






