Security Technical Program Manager
MicrosoftAbout the role
Microsoft’s AI Security Operations team is expanding and we are looking to hire a Security Technical Program Manager to join our team in Redmond, WA.
Be part of a team that builds integrations, solves challenging security problems, develops mechanisms to detect and responds to known attacker methodologies. If you want something that will grow your skills across the security landscape - this is the role for you.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
- Develop high fidelity alerts and signals that is implemented codified with detection as code
- Deploy monitoring and threat simulation testing for security controls to validate efficacy improving on established frameworks
- Perform analysis against logs from a variety of sources (e.g., individual host logs, network traffic logs) to identify potential threats and detection ideas
- Build response workflows and actions that auto-resolve false positives and provide context scaling our ability to investigate
- Support security incident response in a cross-functional environment and drive incident resolution for internal and external threats
- Design and implement attack testing automation to validate detection coverage and build logging pipelines using our custom datasets and infrastructure
- Improve the tooling of threat cluster tracking and intelligence data integration to existing systems and various intelligence feeds
- Respond to security alerts generated in security tooling, driving the incident response process to completion
- Provide advanced security event detection and threat analysis for complex and/or escalated security events
- Provide log/network/malware/device analysis and making recommendations for remediation of security vulnerability conditions
- Validate log sources and indexed data, search through indexed data to optimize search criteria
- Create custom alert schema, reports and custom dashboards
- Perform monitoring, research, assessment and analysis on all notable security events from a variety of technologies such as firewalls, intrusion detection systems, cloud services, endpoint security and operating system events
- Create and follow appropriate pre-defined procedures to further investigate security events and handle escalations to other required personnel as necessary
Other
Qualifications
Required/Minimum Qualifications:
- Bachelor's Degree AND 2+ years experience in engineering, product/technical program management, data analysis, or product development
- OR equivalent experience.
- 1+ year(s) experience managing cross-functional and/or cross-team projects.
- 2+ years of experinence working with industry standard enterprise offerings from leading cybersecurity platforms such as Azure security tech stack, Signal Science, Tenable, Microsoft Defender External Attack Surface Management (EASM), Splunk, BurpSuite Pro, AquaSec, Microsoft Defender
- 2+ years of experience working with Ubuntu/Linux
Preferred Skills:
- Industry certifications: Security+, Certified Information Security Manager (CISM)
- Experience building automated tooling solutions
- Experience with threat modeling and architecture reviews
- Experience with commercial static and dynamic security scanning tools
- Understanding and ability to communicate the techniques, tactics and practices of an attacker to engineers and business stakeholders who are part of a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s