Principal Security Operations Engineer
Microsoft
- Location
- United States, Washington, Redmond
- Work model
- On-Site
- Level
- Principal
- H-1B history
- 2,066 approvals (FY2023)
- Posted
- 3h ago
Skills
About this role
Overview
Quantum computing has the potential to massively accelerate science and technology innovation. Microsoft Discovery & Quantum is building advanced computing platforms, spanning HPC, AI, and quantum, to realize that future. You will join the Quantum Security & IT Operations (QSIT) team protecting a globally distributed research community and its intellectual property. As a Principal Security Operations Engineer in QSIT, you will own the response to cybersecurity, external & insider threat incidents affecting Microsoft Quantum, from initial detection and severity assessment through containment, recovery, root-cause analysis, and executive closure working across National Security Team, HR, Legal, Global Trade, and CISO organizations. You will set the technical direction for incident handling, coordinate responders across Quantum and Microsoft security organizations, and ensure lessons learned translate into durable improvements to controls, detections, and operating procedures. You will also define and drive the requirements for an AI-enabled QSIT Security Operations Center, shaping how AI supports signal enrichment, triage, investigation, response, and analyst decision-making while maintaining strong auditability and data-handling controls. This Principal level role requires broad technical and risk judgment, independent leadership in ambiguous situations, and the ability to influence security strategy across organizational boundaries. This role is onsite in Redmond, WA. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
Responsibilities
Own cybersecurity incidents affecting Microsoft Quantum, establishing severity and response strategy, directing technical investigation and containment, coordinating recovery, and driving incidents to clear, accountable closure. Manage insider and external threat incident analysis and triage from initial indicators through scoping, forensic review, evidence preservation, case disposition, and root-cause analysis, producing defensible investigative narratives for executive, legal, and compliance review. Drive changes to systems and processes based on incident and risk learnings that cross and impact other teams. Lead cross-functional incident response with Quantum engineering, Microsoft CISO organization, National Security Team, HR, Legal, and Global Trade; provide concise executive updates, document decisions and evidence, and ensure post-incident actions are assigned and completed. Define and drive the requirements, architecture, operating model, and prioritized engineering backlog for an AI-enabled QSIT SOC, covering signal enrichment, triage, investigation, response recommendations, analyst-in-the-loop controls, auditability, and sensitive-data handling. Translate AI SOC needs into measurable capabilities and acceptance criteria, evaluate first- and third-party solutions, guide implementation, and assess operational effectiveness, risk, and readiness for production use. Design, implement, and tune insider threat and cybersecurity detections in Microsoft Sentinel and related platforms; onboard and normalize new security data streams; identify visibility gaps; and convert incident findings into improved detections, controls, runbooks, and monitoring coverage. Embody our Culture and Values Qualifications Required/minimum qualifications Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics,