Demo Capital
companies
Jobs

Security Operation Lead

Microsoft

Microsoft

Posted on Jul 1, 2025

Security Operation Lead

Multiple Locations, Costa Rica

Save

Share job

Date posted
Jun 30, 2025
Job number
1838848
Work site
Up to 100% work from home
Travel
0-25 %
Role type
People Manager
Profession
Security Engineering
Discipline
Security Research
Employment type
Full-Time

Overview

Security is one of the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We aim to reshape security and empower every user, customer, and developer with a security cloud that offers end-to-end, simplified solutions.

The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions by ensuring that our company and the broader industry are securing digital technology platforms, devices, and clouds across our customers’ heterogeneous environments, while also protecting our own internal estate.

Our culture is centered on embracing a growth mindset, inspiring excellence, and encouraging teams and leaders to bring their best every day. In doing so, we create life-changing innovations that impact billions of lives around the world.

The Defender Experts for XDR group is looking to hire a Security Operations Lead to help us harness the power of Microsoft’s trillions of security signals. This role involves quickly identifying and reporting the latest human adversary behaviors, generating critical context-rich alerts, building new tools and automations to help customers detect threats, and driving innovations to uncover advanced attacker tradecraft.

This position is 100% remote and requires participation in a weekend rotation.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees, we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day, we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive—at work and beyond.

#MSFTSecurity #Cybersecurity #InfoSec #InformationSecurity #CyberSecurityAwareness #CyberRisk #ThreatIntelligence #CyberAttack #DataProtection #DataPrivacy #GDPR

Qualifications

Required Qualifications:

  • 5+ years of experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), and information technology (IT) operations.
    • OR Master's Degree in Statistics, Mathematics, Computer Science or related field.
  • 5+ years of experience managing a security team.
  • Experience in delivering managed threat hunting service (preferably for large customers).
  • Experience in Security Operations, Threat Intelligence, Cyber Incident Response, or Penetration Testing/Red Teaming.
  • Proficiency in using analysis tools and scripting languages (e.g., Python, SQL, Splunk, PowerBI).
  • Knowledge of Windows OS internals and security mechanisms.
  • Familiarity with cloud infrastructure and authentication/authorization protocols.
  • Understanding of threat analysis models (e.g., Diamond Model, Cyber Kill Chain, MITRE ATT&CK).
  • Fluent in reading, writing and speaking English.

Preferred Qualifications:

  • 7+ years of experience in software development lifecycle, large scale computing, modeling, cyber security, and anomaly detection.
    • OR Doctorate in Statistics, Mathematics, Computer Science or related field.
  • 2+ years of people management experience.
  • 1+ year(s) leading a security function (e.g., Security Operations Center [SOC], threat and vulnerabillity management [TVM]).
  • 1+ year(s) leading multi-disciplinary team.
  • CISSP, CISA, CISM, SANS, GCIA, GCIH, OSCP, and/or Security+ certifications.

Other Requirements:

Ability to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check:

  • This position will be required to pass the Microsoft background and Microsoft Cloud background check upon hire/transfer and every two years thereafter.

Responsibilities

Defender Experts empowers enterprises to detect, investigate, and respond to advanced attacks and data breaches. We are seeking a skilled leader in the security operations space to harness Microsoft's vast security signals, identify the latest adversary behaviors, generate critical alerts, build new hunting tools, and drive innovations in detecting advanced attacker techniques.

People Management

Managers deliver success through empowerment and accountability by modeling, coaching, and caring:

  • Model – Live our culture, embody our values, and practice our leadership principles.
  • Coach – Define team objectives and outcomes, enable success across boundaries, and help the team adapt and learn.
  • Care – Attract and retain great people, understand each individual’s capabilities and aspirations, and invest in the growth of others.

Collaboration

  • Guides the team to work with internal and external stakeholders to deliver service levels that address various threat classes.
  • Advocates for solution requirements and manages relationships with third-party account management teams.

Security Incident Response

  • Leads the team in researching attempted or successful security breaches and aligns resources for next steps.
  • Manages stakeholder communications and coordinates with partner teams to secure data and maintain chain of custody.
  • Collaborates with other security teams to ensure comprehensive analysis and response.
  • Conducts postmortem analyses and demonstrates strong leadership in high-pressure, ambiguous situations.

Monitoring and Detection

  • Guides the team in developing prioritized detection capabilities.
  • Maintains internal stakeholder relationships to ensure awareness and alignment.
  • Oversees the detection of potential or actual intrusions and ensures the team is properly resourced.
  • Drives improvements in first-party products and shares best practices across teams.

Threat Intelligence and Analysis

  • Supports the team in threat analysis and prioritization of analytical efforts.
  • Secures necessary resources and partnerships to address emerging threats.

Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.
Industry leading healthcare
Educational resources
Discounts on products and services
Savings and investments
Maternity and paternity leave
Generous time away
Giving programs
Opportunities to network and connect

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.