
Security Analyst Ii
Microsoft
Job description
Investigate complex security incidents involving cloud, identity, endpoint, and supply chain compromises. Ability to author detection at rapid speed. Conduct root cause analysis, impact assessment, and scope determination. Partner with Detection Engineering, MSTIC, Service Teams, and Incident Response teams to contain and remediate threats. Develop investigative queries, hunting content, playbooks, and automation to improve operational efficiency. Translate investigation findings into actionable security improvements, detections, and process enhancements. Produce clear technical and executive-ready investigation reports. Mentor peers and contribute to investigative best practices and knowledge sharing. Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 1+ year(s) experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 2+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR equivalent experience. These requirements include, but are not limited to the following specialized security screenings: Experience with Sentinel or other detection authoring tools, Experience investigating security incidents in cloud or enterprise environments. Experience using KQL/Kusto, SQL, or similar query languages for log analysis. Understanding of attacker techniques, cloud security, identity security, and the MITRE ATT&CK framework. Strong analytical and communication skills. Experience investigating identity-based attacks, credential theft, OAuth abuse, or cloud compromise scenarios. Experience with supply chain security investigations involving GitHub, npm, or software package ecosystems. Familiarity with AI-assisted investigation workflows and security automation. Security certifications such as GCIH, GCFA, CISSP, GCFE, OSCP, or equivalent.
Verified and listed by ActiveJobs. Applications are made directly on Microsoft's own career page — we never sit in the middle.