The Cyber Defense Investigations – Escalations (CDI-ESC) team is Microsoft's deep-dive investigative arm within Cyber Defense Operations (CDO). We lead the most complex, high-severity, and nation-state security incidents across Microsoft's first-party cloud estate, conducting root cause analysis, blast radius assessment, threat actor attribution, and intelligence-driven hunting. Our work directly disrupts adversaries targeting Microsoft and our customers, and feeds platform-level fixes, detections, and intelligence back into the ecosystem.
Join Microsoft's CDI Escalations team and work at the forefront of cyber defense, investigating the most complex nation-state, supply chain, cloud, and identity-based attacks targeting Microsoft. Our team goes beyond traditional incident response, we combine deep investigations, threat hunting, intelligence operationalization, and cross-organizational collaboration to identify adversaries, drive platform-wide security improvements, and build defenses that prevent future attacks. You'll partner with leaders across MSTIC, GHOST, Detection Engineering, and service teams, leverage AI-powered investigation techniques, and directly influence Microsoft's security posture while solving some of the industry's hardest security challenges.
We are looking for a Senior Security Analyst to join the team!
Starting February, 2026, Microsoft employees are expected to work from a designated Microsoft office at least three days a week if they live within 50 miles (U.S.) or 25 miles (non-U.S., country-specific) of that location. This expectation is subject to local law and may vary by jurisdiction.
Responsibilities
- Lead deep-dive investigations into the most complex and high-severity security incidents, including root cause analysis, blast radius assessment, threat actor attribution, and impact/scope determination.
- Proactively hunt across Microsoft's cloud and identity telemetry (e.g., MSTIC, Kusto/ADX, ArmProd, ESTS) to surface emerging threats and operationalize threat intelligence into queries, notebooks, and detection logic.
- Drive cross-team response for nation-state, supply chain (npm, GitHub, OpenVSX), and identity-based compromises - partnering with MSTIC, OpsHub, Detection Engineering, Evictions, and Service teams to contain and remediate at scale.
- Translate investigation findings into durable improvements - new detections, platform fixes, playbooks, and process changes - so the same class of attack does not succeed twice.
- Raise the bar on investigation quality, contributing to documented standards, peer reviews, and measurable rigor across incidents, hunts, and forensics.
- Leverage AI and Copilot technologies to accelerate triage, evidence collection, and analysis, helping the team stay ahead of attackers operating at machine speed.
- Mentor and uplevel peers in advanced investigation techniques, threat actor tradecraft, and reverse engineering, building a strong culture of investigative excellence.
Qualifications
Required Qualifications:
- Doctorate in Statistics, Mathematics, Computer Science, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
- OR equivalent experience.
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
- Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Preferred Qualifications:
- Bachelor's degree in Computer Science, Information Security, a related technical field, AND 4+ years of experience in cybersecurity, incident response, coordination and presentation with executive level professionals, threat hunting, or security investigations
- OR equivalent experience (6+ years of hands-on security investigation/forensic experience in lieu of degree).
- 3+ years of experience conducting security investigations in large-scale cloud or enterprise environments (Azure, AWS, GCP, or M365).
- Demonstrated experience with log analysis and query languages (KQL/Kusto, SQL, or equivalent) across SIEM, identity, endpoint, or cloud telemetry.
- Working knowledge of modern attacker tradecraft, the MITRE ATT&CK framework, and common cloud/identity attack paths (e.g., token theft, OAuth abuse, supply chain compromise).
- Experience investigating nation-state or financially motivated threat actors and producing attribution-quality analysis.
- Hands-on experience with supply chain compromise investigations (npm, GitHub Actions, OpenVSX, signing/artifact abuse) or identity-plane incidents (Entra ID/AAD, ESTS, federation).
- Familiarity with Microsoft security data sources - MDC, Defender XDR, Sentinel, Azure Resource Graph.
- Experience building or consuming AI/Copilot-assisted investigation tooling, automation, or notebooks to scale analyst workflows.
- Strong written communication - able to produce executive-ready investigation reports, retrospectives, and cross-org technical briefs.
- Industry certifications such as GCFA, GCIH, GCFE, GREM, OSCP, CISSP, or equivalent.
- Prior experience working in CIRT function.
#CISOOrg
Security Operations Engineering IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year.
Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Skills Required
- Doctorate in Statistics, Mathematics, Computer Science, or a related field; or master's degree in one of these fields plus 3+ years of relevant experience; or bachelor's degree plus 4+ years of relevant experience; or equivalent experience.
- Relevant experience in software development lifecycle, large-scale computing, threat modeling, cybersecurity, anomaly detection, SOC detection, threat analytics, SIEM, IT, or operations incident response.
- Ability to meet Microsoft, customer, and/or government security screening requirements.
- Pass the Microsoft Cloud background check upon hire or transfer and every two years thereafter.
- Bachelor's degree in Computer Science, Information Security, or a related technical field, and 4+ years of cybersecurity, incident response, executive coordination and presentation, threat hunting, or security investigations experience; or equivalent experience.
- 3+ years conducting security investigations in large-scale cloud or enterprise environments such as Azure, AWS, GCP, or Microsoft 365.
- Experience with log analysis and query languages such as KQL/Kusto or SQL across SIEM, identity, endpoint, or cloud telemetry.
- Working knowledge of attacker tradecraft, the MITRE ATT&CK framework, and cloud or identity attack paths.
- Experience investigating nation-state or financially motivated threat actors and producing attribution-quality analysis.
- Hands-on experience with supply-chain compromise investigations or identity-plane incidents.
- Familiarity with Microsoft security data sources including MDC, Defender XDR, Sentinel, and Azure Resource Graph.
- Experience building or using AI/Copilot-assisted investigation tooling, automation, or notebooks.
- Strong written communication skills for executive-ready investigation reports, retrospectives, and technical briefs.
- Industry certification such as GCFA, GCIH, GCFE, GREM, OSCP, CISSP, or equivalent.
- Prior experience working in a CIRT function.
Microsoft Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Microsoft and has not been reviewed or approved by Microsoft.
-
Fair & Transparent Compensation — Pay is presented as broadly competitive overall, with clear role/level/location variation and an emphasis on using posted ranges and band information for apples-to-apples comparisons.
-
Retirement Support — Retirement benefits are described as a standout, highlighted by a strong 401(k) match structure and immediate vesting, plus additional plan features for tax-advantaged saving.
-
Parental & Family Support — Family-oriented benefits are portrayed as a meaningful strength, with substantial paid parental leave and added supports like back-up care and adoption/surrogacy assistance.
Microsoft Insights
What We Do
At Microsoft, our mission is to empower every person and every organization on the planet to achieve more. Our mission is grounded in both the world in which we live and the future we strive to create. Today, we live in a mobile-first, cloud-first world, and the transformation we are driving across our businesses is designed to enable Microsoft and our customers to thrive in this world.









