Jobs and Careers
MI

Incident Response Engineer - CIRT

Microsoft
Indiafull_timeVerifiedPosted 31 Jul 2025

About the role

With more than 45,000 employees and partners worldwide, the Customer Experience and Success (CE&S) organization is on a mission to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft’s products and services, ignited by our people and culture. We drive cross-company alignment and execution, ensuring that we consistently exceed customers’ expectations in every interaction, whether in-product, digital, or human-centered. CE&S is responsible for all up services across the company, including consulting, customer success, and support across Microsoft’s portfolio of solutions and products. Join CE&S and help us accelerate AI transformation for our customers and the world.


Within CE&S, the Customer Service & Support (CSS) organization builds trust and confidence for every person and organization through delivering a seamless support experience. In CSS, we are powered by Microsoft’s AI technology to help consumers, businesses, partners, and more, resolve their issues quickly and securely, helping prevent future problems from occurring and achieving more from their Microsoft investment.


As a Senior Incident Response engineer, you will be an elite member of a customer facing security support team leading incident response investigations for Microsoft’s enterprise customers. You have experience in analysing, triaging, scoping, containing, providing guidance for remediation, and determining the root cause of security incidents. You are familiar with collecting and analysing security incident related data to identify indicators of attack and compromise.

In the Customer Service & Support (CSS) team we are looking for people with a passion for delivering customer success. As a Senior Incident Response Engineer you will own, troubleshoot and solve highly complex customer technical issues. This opportunity will allow you to accelerate your career growth by honing your problem-solving, collaboration and research skills, and developing your technical proficiency.

This role is flexible in that you can work up to 100% from home.


Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

 

Interested in security and incident response? Then come join the Cybersecurity Incident Response Team (CIRT) at Microsoft as a security support engineer responsible for helping customers investigate security incidents in their environment.

 

 

Responsibilities

  • Scope customer security incidents
  • Understand and identify indicators of attack and indicators of compromise
  • Analyse incident data from threat analytics tools
  • Communicate recommendations and guidance based on results of security incident analysis to the customer
  • Coordinate a response to the security incident with other Microsoft security and consulting teams.
  • Develop, document, and implement runbooks, capabilities, and techniques for Incident Response
  • Perform security triage and analysis on endpoint, server and network infrastructure.
  • Collaborate with the security intelligence team by providing samples of malware from the customer’s environment
  • Perform activities necessary for immediate containment and short-term resolution of incidents.
  • Maintain current knowledge and understanding of the threat landscape, emerging security threats, and vulnerabilities
  • Investigate root cause of complex security incidents
  • Maintain a high level of confidentiality
  • Participate in the on-call rotation as required

Qualifications

Required/Minimum Qualifications (RQs/MQs)

  • Minimum 2+ years Security Incident Response experience with recent operational security experience (SOC, Malware Analysis, IDS/IPS Analysis, threat analytics, windows server, and endpoint security, etc.)
  • Minimum 1+ years of experience in Network Security Administration, and/or Systems Administration with experience in Windows Server, Windows Client, and Active Directory Administration
  • Minimum 1+ years customer facing experience
  • Experience supporting large and complex geographically distributed enterprise environm

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Microsoft

View company profile →