Microsoft

Principal Security Operations Engineer

Microsoft$142K — $274K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Doctorate in relevant field with 3+ years of relevant experience, or equivalent qualifications with additional years of experience.
  • Deep understanding of software development lifecycle, large-scale computing, cyber security, and incident response.
  • Demonstrated ability in leading complex security incidents from detection to resolution.
  • Hands-on experience with MS Sentinel or similar SIEM tools, including detection engineering and investigative analysis.
  • Strong understanding of insider threat frameworks and experience with compliance functions.

Responsibilities

  • Own cybersecurity incidents for Microsoft Quantum, leading detection, containment, and post-incident closure.
  • Manage both insider and external threat analyses, guiding forensic reviews and narrative development.
  • Implement system changes based on incident learnings to improve security controls.
  • Lead cross-functional incident responses involving various Microsoft teams, providing strategic updates to executives.
  • Define requirements and architecture for an AI-enabled Security Operations Center, prioritizing engineering tasks.
  • Translate AI SOC needs into specific capabilities, assessing risk and operational effectiveness after deployment.
  • Design and refine cybersecurity detections, improving overall monitoring and incident management strategies.

Benefits

  • Comprehensive health benefits including medical, dental, and vision coverage.
  • Retirement plan options with company matching.
  • Generous paid time off and holiday policies.
  • Opportunities for professional development and growth.
  • Inclusive workplace culture that values diversity and collaboration.
Full Job Description
Overview

Quantum computing has the potential to massively accelerate science and technology innovation. Microsoft Discovery & Quantum is building advanced computing platforms, spanning HPC, AI, and quantum, to realize that future. You will join the Quantum Security & IT Operations (QSIT) team protecting a globally distributed research community and its intellectual property.

As a Principal Security Operations Engineer in QSIT, you will own the response to cybersecurity, external & insider threat incidents affecting Microsoft Quantum, from initial detection and severity assessment through containment, recovery, root-cause analysis, and executive closure working across National Security Team, HR, Legal, Global Trade, and CISO organizations. You will set the technical direction for incident handling, coordinate responders across Quantum and Microsoft security organizations, and ensure lessons learned translate into durable improvements to controls, detections, and operating procedures.

You will also define and drive the requirements for an AI-enabled QSIT Security Operations Center, shaping how AI supports signal enrichment, triage, investigation, response, and analyst decision-making while maintaining strong auditability and data-handling controls.

This role requires broad technical and risk judgment, independent leadership in ambiguous situations, and the ability to influence security strategy across organizational boundaries. This role is onsite in Redmond, WA.

Responsibilities

  • Own cybersecurity incidents affecting Microsoft Quantum, establishing severity and response strategy, directing technical investigation and containment, coordinating recovery, and driving incidents to clear, accountable closure.


  • Manage insider and external threat incident analysis and triage from initial indicators through scoping, forensic review, evidence preservation, case disposition, and root-cause analysis, producing defensible investigative narratives for executive, legal, and compliance review.


  • Drive changes to systems and processes based on incident and risk learnings that cross and impact other teams.


  • Lead cross-functional incident response with Quantum engineering, Microsoft CISO organization, National Security Team, HR, Legal, and Global Trade; provide concise executive updates, document decisions and evidence, and ensure post-incident actions are assigned and completed.


  • Define and drive the requirements, architecture, operating model, and prioritized engineering backlog for an AI-enabled QSIT SOC, covering signal enrichment, triage, investigation, response recommendations, analyst-in-the-loop controls, auditability, and sensitive-data handling.


  • Translate AI SOC needs into measurable capabilities and acceptance criteria, evaluate first- and third-party solutions, guide implementation, and assess operational effectiveness, risk, and readiness for production use.


  • Design, implement, and tune insider threat and cybersecurity detections in Microsoft Sentinel and related platforms; onboard and normalize new security data streams; identify visibility gaps; and convert incident findings into improved detections, controls, runbooks, and monitoring coverage.


Embody our Culture and Values

Qualifications

Required/minimum qualifications
  • Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
    • OR equivalent experience.


Other Qualifications
  • Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
    • Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire/transfer and every two years thereafter.
  • Citizenship & Citizenship Verification: This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide proof of citizenship, U.S. permanent residency, or other protected status (e.g., under 8 U.S.C. a7 1324b(a)(3)) for assessment of eligibility to access the export-controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate's citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.Additional or Preferred Qualifications (PQs)

Additional or preferred qualifications
  • Doctorate in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection
    • OR equivalent experience.
    • CISSP CISA CISM SANS OSCP Security+


  • 6+ years of experience in cybersecurity, security operations, incident response, insider threat, threat analytics, security information and event management (SIEM), or equivalent experience.
  • Demonstrated experience leading complex security incidents end-to-end, including technical investigation, containment, recovery, root-cause analysis, executive communication, and post-incident remediation.
  • Hands-on experience with Microsoft Sentinel (KQL) or an equivalent enterprise SIEM, including detection engineering, data onboarding, investigative analysis, and the ability to set technical direction across ambiguous, high-impact security situations.
  • CISSP certification or other relevant (CISA, CISM, SANS GCIA, GCIH, OSCP, Security+).


  • Experience collaborating with corporate insider threat, investigations, legal, or trade compliance functions; exposure to dedicated insider threat platforms such as Purview, DTEX, Proofpoint ITM, Magnet Axiom, or Forcepoint.


  • Experience designing, deploying, or evaluating agentic AI or LLM-based automation in a security operations context is strongly desired; familiarity with post-quantum cryptography concepts and CNSA 2.0.


  • Experience or interest in the specific challenges of protecting strategic research programs from sustained external targeting; familiarity with export control (EAR / ITAR) and government program environments.

#Quantum #QuantumCareers #MDQCareers #Security

Security Operations Engineering IC5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year.

Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:
https://careers.microsoft.com/us/en/us-corporate-pay

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

About Microsoft

Microsoft is an American multinational corporation that develops, manufactures, licenses, supports, and sells a range of software products and services. Microsoft’s devices and consumer (D&C) licensing segment licenses the Windows operating system and related software, Microsoft Office for consumers, and the Windows Phone operating system. The company’s computing and gaming hardware segment provides Xbox gaming and entertainment consoles and accessories, second-party and third-party video games, and Xbox Live subscriptions; surface devices and accessories; and Microsoft PC accessories. Its phone hardware segment offers Lumia smartphones and other non-Lumia phones. Its D&C segment provides Windows Store, Xbox Live transactions, and Windows phone store; search advertising; display advertising; Office 365 Home and Office 365 Personal; first-party video games; and other consumer products and services as well as operating retail stores. Microsoft’s commercial licensing segments license server products, including Windows Server, Microsoft SQL Server, Visual Studio, System Center, and related Client Access Licenses (CALs); Windows Embedded; Windows operating system; Microsoft Office for business, including Office, Exchange, SharePoint, Lync, and related CALs; Microsoft Dynamics business solutions; and Skype. Its commercial segment offers enterprise services, including premier support services and Microsoft consulting services; commercial cloud comprising Office 365 Commercial, other Microsoft Office online offerings, Dynamics CRM Online, and Microsoft Azure; and other commercial products and online services. The company markets and distributes its products through original equipment manufacturers, distributors, and resellers, as well as online.

Microsoft Careers

Join Microsoft today and be part of a company that values innovation, leadership, and diversity in its workforce. As a global leader in technology and digital transformation, Microsoft offers unparalleled job opportunities that propel your career to new heights.

Explore Career Opportunities at Microsoft

Whether you're a seasoned professional looking for your next challenge or a recent graduate eager to start your career, Microsoft has a position that suits your skills and ambitions. We are committed to fostering a culture of growth and learning, where every team member is supported in expanding their horizons.

Internship Programs

Kickstart your career with a Microsoft internship. Our internships provide invaluable workplace experience and networking opportunities in a supportive and dynamic environment. You'll work on real projects, learn from industry leaders, and gain the skills necessary for a successful career in technology.

Employment Benefits

Choosing a career at Microsoft means more than just a job. Our employees enjoy a range of benefits designed to empower them both professionally and personally. These include comprehensive health benefits, flexible working conditions, and opportunities for career advancement through professional development and diversity training.

Inclusive Culture and Diversity

At Microsoft, we believe that innovation comes from diversity of thought and inclusion. We are committed to a workplace where everyone feels valued and inspired. Our leadership is dedicated to fostering an environment where diverse perspectives lead to breakthrough innovations and a competitive edge.

Grow with Us

Career growth at Microsoft is about more than climbing the corporate ladder; it's about continuous learning, expanding your skills, and improving your capabilities. With access to various leadership and training programs, you can evolve as a professional and make a significant impact within the company and on the global stage.

Hiring Process

Our hiring process is designed to identify true potential. Starting with a review of your resume, followed by interviews that assess your problem-solving abilities and cultural fit, we ensure that all candidates have a fair chance to demonstrate their strengths and potential to contribute to our team.

Networking and Professional Development

Microsoft is a place where you can build a professional network that spans the globe. Our employees benefit from connections with top-tier professionals and industry leaders, which opens doors to innovative projects and collaborative opportunities that are second to none.

Join Our Team

If you're ready to take on exciting challenges and make a difference in the world of technology, explore the job opportunities at Microsoft. Search for open positions that match your skills and interests, and prepare to embark on a rewarding career path filled with innovation and opportunities for personal and professional growth.

Stay Connected

Keep up to date with the latest at Microsoft Careers by subscribing to our job alert emails. Get tailored content that aligns with your career preferences and discover the exciting and rewarding opportunities that await at Microsoft.

SEARCH MICROSOFT JOBS

At Microsoft, your future is limitless. Join us in our mission to empower every person and every organization on the planet to achieve more. Your journey with Microsoft starts here.
Learn more about Microsoft
Size
181,000 employees
Market Cap
$1,762.4 billion
Industry
Net Income
$51.3 billion
Founded
1975
5 Year Trend
+15.5%
Revenue
$153.2 billion
NASDAQ

Similar Jobs

More Jobs at Microsoft

More Information Technology Jobs

Find similar Principal Security Operations Engineer jobs: