This role serves as the senior subject matter expert for cloud incident response across Microsoft Azure and Microsoft 365. You will lead high‑impact investigations, mentor responders, and continuously improve the speed, quality, and repeatability of cloud incident response operations. This position is ideal for an experienced cloud security engineer, architect, or incident responder who thrives in complex investigations and wants to shape how cloud response is done at scale. In this role you will: Lead Azure and Microsoft 365 security investigations, including identity compromise, privilege escalation, persistence, data exfiltration, and abuse of cloud services Act as the senior escalation point for complex cloud investigations, providing investigative direction and response strategy Perform investigations using Azure Activity Logs, Entra ID logs, Microsoft 365 Unified Audit Log, Defender telemetry, and related forensic artifacts Develop and standardize cloud‑specific incident response playbooks to improve consistency and efficiency Stay current with evolving attack techniques and security technologies to design, build, and continuously refine cloud detections and alerts across Azure and Microsoft 365 Participate in an on‑call rotation as needed to support timely response to security incidents outside of standard business hours
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
High school or GED