Ref. No. a0MP900000AJA17MAH
- Dynamics 365 Finance & Ops
Description
What You Will Do
Independently lead complex investigations involving multiple systems, technologies, data sources, or security domains.
Correlate endpoint, identity, network, cloud, email, application, and threat intelligence data to determine incident scope, cause, impact, confidence, and required response.
Coordinate technical response activities for significant security incidents and provide timely stakeholder communications.
Conduct root cause analysis and develop practical corrective and preventive recommendations.
Develop, tune, test, and document security detections, correlation rules, investigative procedures, and response playbooks.
Develop scripts, queries, integrations, and workflow automation that improve investigation quality, response time, and service consistency.
Lead vulnerability analysis and risk-based remediation discussions with system owners, clients, and technical teams.
Lead technical discussions with clients and translate findings into clear business and risk implications.
Review analyst investigations, reports, case documentation, and recommendations for quality, accuracy, and completeness.
Mentor analysts and provide technical guidance during investigations, escalations, and operational initiatives.
Serve as the operational owner for an assigned security platform, process, service component, procedure, or technical capability.
Identify material gaps in logging, monitoring, detection coverage, response procedures, or service delivery and lead corrective improvements.
Operates independently with minimal oversight.
Demonstrates advanced technical expertise across multiple security domains.
Exercises strong risk-based judgment and communicates recommendations clearly.
Serves as a trusted technical resource, reviewer, and mentor.
What You Will Bring
Bachelor's degree in Cybersecurity, Information Technology or equivalent practical experience
5-8 years of relevant cybersecurity experience, including substantial hands-on security operations or incident response responsibility
Demonstrated experience independently leading complex investigations and response activities
Experience with Microsoft Defender, Microsoft Sentinel, Entra ID, Azure security technologies, and the Microsoft security ecosystem
Experience with cloud security monitoring and cloud security posture management technologies
Familiarity with SOC 2, ISO 27001, NIST Cybersecurity Framework, PCI DSS, and related compliance frameworks
Experience supporting or governing third-party managed security service providers
Experience with phishing simulations, security awareness campaigns, and related communications
Relevant certifications such as Security+, CySA+, GSEC, SC-200, GCIH, GCIA, GCED, GMON, AZ-500, CISSP, or equivalent demonstrated expertise are strongly preferred
Experience developing detections, automations, operational improvements, or security workflows
Experience presenting technical findings and risk information to clients, business leaders, and technical teams
Strong understanding of threat detection, incident response methodologies, and security operations practices
This role will be based in our Carmel office in a hybrid capacity