Jobs · Washington

Principal Technical Advisor for Cybersecurity Incident Response

Microsoft · Redmond, WA · 2 wk ago
Hybrid$131k–$277k/yrFull-time

About the role

With more than 45,000 employees and partners worldwide, the Customer Experience and Success (CE&S) organization is on a mission to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft’s products and services, ignited by our people and culture. We drive cross-company alignment and execution, ensuring that we consistently exceed customers’ expectations in every interaction, whether in-product, digital, or human-centered. CE&S is responsible for all up services across the company, including consulting, customer success, and support across Microsoft’s portfolio of solutions and products.

Within CE&S, the Customer Service & Support (CSS) organization builds trust and confidence for every person and organization through delivering a seamless support experience. In CSS, we are powered by Microsoft’s AI technology to help consumers, businesses, partners, and more, resolve their issues quickly and securely, helping prevent future problems from occurring and achieving more from their Microsoft investment.

The Principal Technical Advisor for Cybersecurity Incident Response is a service delivery focused subject matter expert. You will be responsible for Cybersecurity Incident Response Team (CIRT) support engineer staff technical readiness and process compliance. You will provide in-depth technical & subject matter expertise for cybersecurity Incident Response scenarios all while driving delivery excellence in a collaborative environment to achieve superior customer outcomes. Your primary accountability is to support staff and managers on the teams you work with. This opportunity enables and promotes career growth as a recognized technical Subject Matter Expert (SME).

Responsibilities

  • Case Management (Delivery Excellence): Demonstrate expert problem-solving, case management, and customer service skills. Strategize technical triages and provide actionable feedback to key partners and stakeholders.
  • Managing Collaboration Activities: Handle complex escalated problems, partner with product teams to drive fixes, and identify trends in customer feedback for future product enhancements.
  • Process Improvement: Refine processes by partnering with senior leadership across global teams, lead efforts to improve diagnostic data logging, and facilitate communication between engineering and support teams. Serve as an early warning system and put plans in place to mitigate issues and proactively drive solutions.
  • Define and evolve engagement models, capability readiness, and service delivery frameworks for incident response.
  • Serve as a recognized expert in incident response and threat investigation, specializing in Cloud (Azure, Microsoft 365) and Windows environments; adversary behaviors, compromise analysis, and detection techniques.
  • Provide technical leadership in investigations requiring advanced forensic and investigative judgment under time pressure; decision-making with incomplete data and high business impact.
  • Influence standards for data handling, investigative rigor, and compliance across CIRT operations.

Requirements

  • Bachelor's Degree in Information Technology (IT), Computer Science, Business Administration, Electrical Engineering, or Business Leadership AND 8+ years system development, network operations, software support, IT, consulting, or technical troubleshooting experience OR equivalent experience.
  • 8+ years prior product, customer support and/or technical support experience.
  • Ability to meet Microsoft, customer and/or government security screening requirements, including Microsoft Cloud Background Check (required upon hire/transfer and every two years thereafter).
  • Citizenship verification: This role requires access to export-controlled information. Proof of citizenship or U.S. permanent residency/protected status is required as a condition of employment.
  • This position supports U.S. federal, state, and/or local government agency customers and is subject to citizenship-based legal restrictions. Verification of citizenship with a valid passport is required.

Qualifications

  • Bachelor's Degree in Information Technology (IT), Computer Science, Business Administration, Electrical Engineering, or Business Leadership AND 15+ years system development, network operations, software support, IT, consulting, or technical troubleshooting experience OR equivalent experience.
  • 5+ years experience in Cybersecurity Incident Response.
  • SC-900 and ISC2 CC certifications; CISSP a plus.
  • 10+ years prior product, customer support and/or technical support experience.
  • AI-900 certification or AI-901 certification.
  • Technologies certifications for business area (e.g., M365 Technologies, Security Certifications, Azure Certifications).

Pay

The typical base pay range for this role across the U.S. is USD $130,900 - $277,200 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $165,600 - $303,600 per year. Certain roles may be eligible for benefits and other compensation.

Similar jobs