Cybersecurity Lead Investigator

Microsoft•,
•$119,800 - $261,000

About The Position

Microsoft's Detection and Response Team (DART) is seeking a skilled and experienced Cybersecurity Lead Investigator to join the team. DART is the first port of call for many customers during a security incident. This pivotal, customer-facing role calls for a technically deep and agile investigator who can lead complex, high-impact incident response across on-premises and cloud environments and turn incomplete evidence into clear, defensible response decisions. You will lead the investigation, establish technical priorities and act as the primary technical point of contact for customers, including executive stakeholders. Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. Incident coordinators support staffing, scheduling and operational escalation; the Lead Investigator owns investigation direction and technical judgement within the agreed engagement scope. As part of a globally distributed, mission-driven team, you will share research, mentor colleagues and help shape the future of Defender Experts Cybersecurity Incident Response. Microsoft's mission is to empower every person and every organization on the planet to achieve more. Employees are expected to demonstrate a growth mindset, innovation, collaboration, respect, integrity, accountability, and inclusion.

Requirements

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
  • Verification of U.S. citizenship due to citizenship-based legal restrictions applicable to the role.
  • Ability to meet Microsoft, customer and / or government security screening requirements.
  • Must pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.

Nice To Haves

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
  • Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions.
  • Lead and manage high-profile incident response efforts for some of the world’s largest businesses.
  • Coordinate and lead all key stakeholders as the primary point of contact for major incidents. (This could include technical teams, executives, consultants, and partners)
  • Identify gaps early in the engagement process and request appropriate resources to fill those gaps.
  • Balance the need for rapid recovery with data collection and evidence preservation.
  • Direct activities to secure Enterprise-scale environments and assess potential data exfiltration or data collection.
  • Management of large-scale incidents in a follow-the-sun format working with fellow team members from across the globe.
  • Contextual application of MITRE Attack Framework and or OSI Model.
  • Delivery of complex and technical discussions effectively to customer representatives of varying levels.
  • Security Certifications in any of the following: OSCP, CISSP, SANS Certifications, SC Certifications from Microsoft.
  • Experience working with methods utilized for evidence collection, maintenance of chain of custody and associated documentation, evidence storage and analysis, and evidentiary reporting.
  • Eligibility to obtain or currently active government security clearance.
  • Experience analysing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations.
  • Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability.
  • Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information.

Responsibilities

  • Orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers.
  • Contextualize and prioritize findings to put together a comprehensive account and briefing of the events that transpired during a security incident.
  • Pull together multiple disparate events to build and communicate a cohesive timeline of activity.
  • Collaborate with stakeholders at every level of the business, including legal, compliance, cybersecurity, engineering, and executive functions.
  • Communicate key objectives and results with clarity and context.
  • Manage all the complexities of large-scale cybersecurity investigations for global multi-national organizations, serving as the primary point of contact.
  • Lead research and analysis of security threats, and sharing findings across the team.
  • Identify, conduct, and support others in conducting research into critical security areas, such as current attacks, adversary tracking, and academic literature.
  • Analyze complex issues using multiple data sources to develop insights and identify security problems and threats.
  • Create new solutions to mitigate security issues.
  • Recommend prioritization and validation methods for technical indicators, developing tools to automate analyses.
  • Lead efforts to clean, structure, and standardize data and data sources; lead data quality efforts to ensure timely and consistent access to data sources.
  • Develop written content for publication on Microsoft blog platforms.
  • Develop presentations for delivery at internal and external conferences.
  • Use the unique experiences of Microsoft Incident Response to create unique storytelling moments.
  • Lead from the front by ideating, mentoring, and supporting thought leadership efforts across the team.
  • Complete operational tasks and readiness with timeliness and accuracy.
  • Follow Microsoft policies, compliance, and procedures (e.g., Enterprise Services Authorization Policy, Standards of Business Conduct, labor logging, expenses, travel guidelines).
  • Lead by example and guide team members on operational tasks, readiness, and compliance.

Benefits

  • Certain roles may be eligible for benefits and other compensation.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service