Microsoft Logo

Microsoft

Cybersecurity Lead Investigator

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in AU
Senior level
Remote
Hiring Remotely in AU
Senior level
Lead complex cybersecurity incident investigations across on-premises and cloud environments. Set investigative objectives, analyze evidence, reconstruct timelines, assess compromise and exfiltration, and direct containment and recovery recommendations. Serve as the primary technical contact for customers and executives, coordinate specialists, manage investigative risks and dependencies, maintain documentation, and mentor colleagues. The role requires customer-facing communication, global follow-the-sun collaboration, and flexibility for non-standard hours.
The summary above was generated by AI
Overview

With more than 45,000 employees and partners worldwide, the Customer Experience and Success (CE&S) organization is on a mission to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft's products and services, ignited by our people and culture. We drive cross-company alignment and execution, ensuring that we consistently exceed customers' expectations in every interaction, whether in-product, digital, or human-centered. CE&S is responsible for all up services across the company, including consulting, customer success, and support across Microsoft's portfolio of solutions and products. Join CE&S and help us accelerate AI transformation for our customers and the world.

Microsoft's Detection and Response Team (DART) is seeking a skilled and experienced Cybersecurity Lead Investigator to join the team in Australia. DART is the first port of call for many customers during a security incident. This pivotal, customer-facing role calls for a technically deep and agile investigator who can lead complex, high-impact incident response across on-premises and cloud environments and turn incomplete evidence into clear, defensible response decisions.

You will lead the investigation, establish technical priorities and act as the primary technical point of contact for customers, including executive stakeholders. Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. Incident coordinators support staffing, scheduling and operational escalation; the Lead Investigator owns investigation direction and technical judgement within the agreed engagement scope.

As part of a globally distributed, mission-driven team, you will share research, mentor colleagues and help shape the future of Defender Experts Cybersecurity Incident Response. Microsoft's mission is to empower every person and every organization on the planet to achieve more. Employees are expected to demonstrate a growth mindset, innovation, collaboration, respect, integrity, accountability, and inclusion.


Responsibilities

As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers.

  • Set investigation objectives, hypotheses, priorities and evidence requirements; lead hands-on analysis and specialist workstreams across enterprise on-premises and cloud environments.
  • Contextualise and prioritise findings, correlate disparate evidence and build cohesive incident timelines. Establish what is known, what remains uncertain and what additional collection or analysis is needed.
  • Assess adversary activity, compromise scope and potential data collection or exfiltration; validate key findings and explain the confidence and limitations of conclusions.
  • Direct technical response planning and recommendations to secure enterprise environments, balancing containment and recovery urgency with evidence preservation and customer business constraints. Coordinate execution with customer-authorised teams and relevant specialists.
  • Serve as the primary technical point of contact for complex investigations; brief technical teams, executives, legal, compliance, engineering and other stakeholders with clear objectives, findings and decision options.
  • Identify skill, access, telemetry and resource gaps early; work with incident coordinators and leadership to resolve dependencies, obtain specialist support and escalate delivery risks.
  • Maintain investigative documentation and clear follow-the-sun handovers covering evidence, hypotheses, decisions, risks and next actions; support final reporting and lessons learned.

Qualifications
Required / Minimum Qualifications
  • A relevant degree in Computer Science, Computer Security, Statistics, Mathematics or a related field, or equivalent practical experience in cybersecurity, incident management or related operations, AND 5+ years of industry experience.
  • Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions.
  • Ability to correlate and assess evidence from multiple sources, reconstruct incident timelines, evaluate compromise scope and possible exfiltration, and clearly explain findings and uncertainty.
  • Experience directing response activities while balancing rapid recovery, technical dependencies and business impact.
  • Demonstrated ability to lead technical specialists and stakeholders, identify engagement gaps, request appropriate resources and manage investigations using a global follow-the-sun model.
  • Demonstrable customer-facing written and verbal communication, including executive briefings.
  • Flexibility to work non-standard business hours that may include evening, nighttime, weekends, and/or holidays.
Preferred Qualifications
  • Experience analysing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations.
  • Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability.
  • Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information.
Citizenship & Citizenship Verification

This position requires verification of Australian citizenship due to citizenship-based legal restrictions. Specifically, this position supports Australian government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport.

Security Clearance Requirements

Ability to meet Microsoft, customer and / or government security screening requirements are required for this role.  These requirements include but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.



#DART


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Similar Jobs

Yesterday
Remote
Queensland, AUS
Entry level
Entry level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Perform deep maintenance, inspections, structural repairs, composite repairs, modifications, corrosion rectification, and component replacement on F/A-18F Super Hornet aircraft. Interpret engineering drawings and technical publications, complete maintenance documentation, and ensure compliance with safety, quality, airworthiness, and aviation regulatory requirements. The role requires precision workmanship in a regulated military aviation environment and offers opportunities to develop advanced composite repair expertise.
Top Skills: Aircraft Corrosion RectificationAircraft Structural MaintenanceCasaComposite RepairDasrEngineering DrawingsMetallic Structure RepairTechnical Manuals
2 Days Ago
Remote or Hybrid
Australia
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Own territory growth across Australia’s digital native and startup segment by winning new customers and expanding existing accounts. Manage the full technology sales cycle, from prospecting and discovery through technical validation, negotiation, and close. Build relationships with founders, executives, engineering, infrastructure, and security leaders. Develop territory plans, maintain pipeline discipline, forecast accurately, leverage ecosystem partners, and support onboarding, adoption, and renewal activities.
Top Skills: Ai ToolsApplication SecurityCloud InfrastructureComputer NetworkingGoogle WorkspaceModern Developer PlatformsSalesforceTableau
2 Days Ago
Remote or Hybrid
Internship
Internship
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Supports the ANZ HR team with People & Culture programs, HR communications, learning and development initiatives, employee lifecycle processes, onboarding, benefits, engagement, personnel file maintenance, and employee portal updates. The intern will use data and research to improve employee experience, collaborate on people-related initiatives, and assist with virtual and in-person events. This is a part-time, nine-month internship requiring enrollment throughout the placement.
Top Skills: Adobe ExpressExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft Word

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account