Microsoft

Incident Command & Threat Hunting Operations Manager

Microsoft$119K — $234K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Doctorate or Master's in Statistics, Mathematics, Computer Science, or related field with relevant experience in security and incident response
  • 4-8 years of experience in software development, cyber security, and threat modeling based on education level
  • 1+ years of management experience leading security functions or multi-disciplinary teams
  • Preferred certifications such as CISSP, CISA, CISM, or relevant security credentials
  • Experience in incident response and managing high-severity incidents in complex environments.
  • Familiarity with analytics and threat detection tools like Kusto or ServiceNow.

Responsibilities

  • Lead governance of Major Incident processes including classification and escalation
  • Act as authority during high-severity incidents, coordinating cross-functional efforts
  • Develop and coach a team of Major Incident Leads for incident management
  • Define and execute threat hunting strategies across Fraud Operations
  • Integrate incident learnings into threat detection methods and improvements
  • Coordinate between various teams for effective incident and threat response
  • Establish metrics for operational excellence in response and threat detection

Benefits

  • Comprehensive health, dental, and vision insurance
  • 401(k) plan with company match
  • Generous paid time off and holidays
  • Opportunities for professional development and advancement
  • Access to wellness programs and resources
Full Job Description
Overview

The Incident Command & Threat Hunting Operations Manager is responsible for leading end-to-end incident response governance and proactive threat detection across Fraud & Abuse Security operations. This role ensures rapid, coordinated response to high-severity incidents while driving threat hunting programs that identify and disrupt adversarial activity before impact.

The role operates at the intersection of incident command, threat intelligence, and operational execution, delivering measurable reduction in customer and Microsoft harm through structured processes, data-driven decision-making, and cross-organizational coordination.

Responsibilities

1. Incident Command Leadership & Governance
  • Own and evolve the Major Incident governance model, including severity definitions, escalation pathways, and decision authority
  • Act as incident command authority for high-severity (Sev A / Sev 1) or systemic incidents
  • Coordinate cross-functional response across engineering, fraud, security, and product teams
  • Ensure incidents are driven to resolution with clear ownership, timelines, and accountability
  • Oversee incident classification, severity validation, and escalation consistency
  • Sponsor and drive post-incident reviews (PIRs) to address root cause and systemic gaps

2. Major Incident Lead Management
  • Lead and develop a team of Major Incident Leads (MILs) or equivalent responders
  • Assign and support leadership coverage across incidents and priority workstreams
  • Coach incident leads on:
    • Command and control execution
    • Prioritization and trade-off decisions
    • Stakeholder alignment and communication
  • Step in to stabilize incidents that stall, escalate improperly, or degrade in quality

3. Threat Hunting Strategy & Execution
  • Define and operationalize threat hunting strategy and standards across Fraud Ops ecosystems
  • Lead proactive hunts targeting:
    • Undetected adversary activity
    • Fraud patterns and abuse campaigns
    • Emerging attack techniques and TTPs
  • Ensure hunts are hypothesis-driven, intelligence-informed, and measurable
  • Drive integration of threat intelligence, telemetry, and analytics into hunting workflows

4. Threat Hunt Lead Management
  • Lead and develop a team of Threat Hunt Leads (THLs) or equivalent responders
  • Assign and support leadership coverage across Hunts and priority workstreams
  • Coach incident leads on:
    • Threat Hunt execution
    • Prioritization and trade-off decisions
    • Stakeholder alignment and communication
  • Step in to stabilize Hunts that stall, escalate improperly, or degrade in quality

5. Incident-Threat Hunting Integration
  • Ensure seamless integration between:
    • Reactive incident response
    • Proactive threat hunting
    • Detection engineering and automation
  • Translate incident learnings into:
    • New detections
    • Hunting hypotheses
    • Process and tooling improvements
  • Drive closed-loop improvement model across incidents and hunts

6. Cross-Organizational Coordination
  • Serve as a central coordination point across:
    • Fraud Operations
    • Cyber Defense Operations
    • Engineering and product teams
    • Threat intelligence and detection teams
  • Mobilize appropriate stakeholders during incidents and threat hunts
  • Ensure consistent execution across distributed teams and geographies

7. Operational Excellence & Metrics
  • Define and track key performance indicators:
    • Time to detect (TTD)
    • Time to mitigate (TTM)
    • Incident containment effectiveness
    • Threat hunting yield and impact
  • Establish audit-ready processes and documentation standards
  • Drive continuous improvement across:
    • Incident lifecycle management
    • Threat detection effectiveness
    • Operational efficiency

8. Strategy, Governance & Risk Reduction
  • Align operations to Fraud-first principles and financial harm reduction
  • Ensure policy alignment, compliance, and enforcement consistency
  • Define operational strategies for:
    • Risk prioritization
    • Resource allocation
    • Capability development (automation, tooling, analytics)
  • Influence roadmap for incident response and threat hunting capabilities

Leadership Expectations
  • Operates as a decisive incident commander under pressure
  • Drives clarity in ambiguity and resolves decision bottlenecks
  • Balances strategic foresight with tactical execution
  • Demonstrates systems thinking across incident response and threat detection
  • Builds high-performing teams and elevates senior IC capability

Impact
  • Reduces customer and Microsoft financial harm
  • Improves time-to-detect and time-to-contain threats
  • Increases operational rigor and audit defensibility
  • Enables scalable, repeatable incident response and threat hunting practices
  • Strengthens Microsoft's security posture against fraud, abuse, and advanced threats


Qualifications

Required Qualifications
  • Doctorate in Statistics, Mathematics, Computer Science, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR equivalent experience.

Preferred Qualifications
  • Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR equivalent experience.
  • 1+ year(s) people management and/or team leadership experience, including leading security functions (e.g., SOC, TVM) and multi-disciplinary teams.
  • Relevant certifications preferred (CISSP, CISA, CISM, SANS, OSCP, Security+).
  • Experience in incident response, incident command, threat hunting/detection, and Security Operations (SOC/SecOps).
  • Experience managing high-severity incidents and crisis response at scale.
  • Understanding of adversary tactics, techniques, and procedures (TTPs), threat intelligence integration, and incident management frameworks (e.g., MFIRP, ICS).
  • Experience leading cross-functional teams in complex environments and fraud/abuse ecosystems (e.g., Azure, M365, Partner Center).
  • Familiarity with Kusto, telemetry analysis, ServiceNow or similar case management platforms, and detection engineering/automation pipelines.
  • Experience building operational frameworks, RACI models, and governance structures.


Security Operations Engineering M4 - The typical base pay range for this role across the U.S. is USD $119,800.00 - $234,700.00 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200.00 - $261,000.00 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

About Microsoft

Microsoft is an American multinational corporation that develops, manufactures, licenses, supports, and sells a range of software products and services. Microsoft’s devices and consumer (D&C) licensing segment licenses the Windows operating system and related software, Microsoft Office for consumers, and the Windows Phone operating system. The company’s computing and gaming hardware segment provides Xbox gaming and entertainment consoles and accessories, second-party and third-party video games, and Xbox Live subscriptions; surface devices and accessories; and Microsoft PC accessories. Its phone hardware segment offers Lumia smartphones and other non-Lumia phones. Its D&C segment provides Windows Store, Xbox Live transactions, and Windows phone store; search advertising; display advertising; Office 365 Home and Office 365 Personal; first-party video games; and other consumer products and services as well as operating retail stores. Microsoft’s commercial licensing segments license server products, including Windows Server, Microsoft SQL Server, Visual Studio, System Center, and related Client Access Licenses (CALs); Windows Embedded; Windows operating system; Microsoft Office for business, including Office, Exchange, SharePoint, Lync, and related CALs; Microsoft Dynamics business solutions; and Skype. Its commercial segment offers enterprise services, including premier support services and Microsoft consulting services; commercial cloud comprising Office 365 Commercial, other Microsoft Office online offerings, Dynamics CRM Online, and Microsoft Azure; and other commercial products and online services. The company markets and distributes its products through original equipment manufacturers, distributors, and resellers, as well as online.

Microsoft Careers

Join Microsoft today and be part of a company that values innovation, leadership, and diversity in its workforce. As a global leader in technology and digital transformation, Microsoft offers unparalleled job opportunities that propel your career to new heights.

Explore Career Opportunities at Microsoft

Whether you're a seasoned professional looking for your next challenge or a recent graduate eager to start your career, Microsoft has a position that suits your skills and ambitions. We are committed to fostering a culture of growth and learning, where every team member is supported in expanding their horizons.

Internship Programs

Kickstart your career with a Microsoft internship. Our internships provide invaluable workplace experience and networking opportunities in a supportive and dynamic environment. You'll work on real projects, learn from industry leaders, and gain the skills necessary for a successful career in technology.

Employment Benefits

Choosing a career at Microsoft means more than just a job. Our employees enjoy a range of benefits designed to empower them both professionally and personally. These include comprehensive health benefits, flexible working conditions, and opportunities for career advancement through professional development and diversity training.

Inclusive Culture and Diversity

At Microsoft, we believe that innovation comes from diversity of thought and inclusion. We are committed to a workplace where everyone feels valued and inspired. Our leadership is dedicated to fostering an environment where diverse perspectives lead to breakthrough innovations and a competitive edge.

Grow with Us

Career growth at Microsoft is about more than climbing the corporate ladder; it's about continuous learning, expanding your skills, and improving your capabilities. With access to various leadership and training programs, you can evolve as a professional and make a significant impact within the company and on the global stage.

Hiring Process

Our hiring process is designed to identify true potential. Starting with a review of your resume, followed by interviews that assess your problem-solving abilities and cultural fit, we ensure that all candidates have a fair chance to demonstrate their strengths and potential to contribute to our team.

Networking and Professional Development

Microsoft is a place where you can build a professional network that spans the globe. Our employees benefit from connections with top-tier professionals and industry leaders, which opens doors to innovative projects and collaborative opportunities that are second to none.

Join Our Team

If you're ready to take on exciting challenges and make a difference in the world of technology, explore the job opportunities at Microsoft. Search for open positions that match your skills and interests, and prepare to embark on a rewarding career path filled with innovation and opportunities for personal and professional growth.

Stay Connected

Keep up to date with the latest at Microsoft Careers by subscribing to our job alert emails. Get tailored content that aligns with your career preferences and discover the exciting and rewarding opportunities that await at Microsoft.

SEARCH MICROSOFT JOBS

At Microsoft, your future is limitless. Join us in our mission to empower every person and every organization on the planet to achieve more. Your journey with Microsoft starts here.
Learn more about Microsoft
Size
181,000 employees
Market Cap
$1,762.4 billion
Industry
Net Income
$51.3 billion
Founded
1975
5 Year Trend
+15.5%
Revenue
$153.2 billion
NASDAQ

Similar Jobs

More Jobs at Microsoft

More Information Technology Jobs

Find similar Incident Command & Threat Hunting Operations Manager jobs: