For Employers

Microsoft

Cybersecurity Lead Investigator

Posted 5 days ago
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The Lead Investigator orchestrates evidence-driven cybersecurity investigations and directs technical incident response across cloud and on-premises environments. They serve as the primary technical point of contact for customers and stakeholders, ensuring clear communication of findings and response recommendations.

Overview

With more than 45,000 employees and partners worldwide, the Customer Experience and Success (CE&S) organization is on a mission to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft's products and services, ignited by our people and culture. We drive cross-company alignment and execution, ensuring that we consistently exceed customers' expectations in every interaction, whether in-product, digital, or human-centered. CE&S is responsible for all up services across the company, including consulting, customer success, and support across Microsoft's portfolio of solutions and products. Join CE&S and help us accelerate AI transformation for our customers and the world.

Microsoft's Detection and Response Team (DART) is seeking a skilled and experienced Cybersecurity Lead Investigator to join the team in Australia. DART is the first port of call for many customers during a security incident. This pivotal, customer-facing role calls for a technically deep and agile investigator who can lead complex, high-impact incident response across on-premises and cloud environments and turn incomplete evidence into clear, defensible response decisions.

You will lead the investigation, establish technical priorities and act as the primary technical point of contact for customers, including executive stakeholders. Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. Incident coordinators support staffing, scheduling and operational escalation; the Lead Investigator owns investigation direction and technical judgement within the agreed engagement scope.

As part of a globally distributed, mission-driven team, you will share research, mentor colleagues and help shape the future of Defender Experts Cybersecurity Incident Response. Microsoft's mission is to empower every person and every organization on the planet to achieve more. Employees are expected to demonstrate a growth mindset, innovation, collaboration, respect, integrity, accountability, and inclusion.



Responsibilities

As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers.

  • Set investigation objectives, hypotheses, priorities and evidence requirements; lead hands-on analysis and specialist workstreams across enterprise on-premises and cloud environments.
  • Contextualise and prioritise findings, correlate disparate evidence and build cohesive incident timelines. Establish what is known, what remains uncertain and what additional collection or analysis is needed.
  • Assess adversary activity, compromise scope and potential data collection or exfiltration; validate key findings and explain the confidence and limitations of conclusions.
  • Direct technical response planning and recommendations to secure enterprise environments, balancing containment and recovery urgency with evidence preservation and customer business constraints. Coordinate execution with customer-authorised teams and relevant specialists.
  • Serve as the primary technical point of contact for complex investigations; brief technical teams, executives, legal, compliance, engineering and other stakeholders with clear objectives, findings and decision options.
  • Identify skill, access, telemetry and resource gaps early; work with incident coordinators and leadership to resolve dependencies, obtain specialist support and escalate delivery risks.
  • Maintain investigative documentation and clear follow-the-sun handovers covering evidence, hypotheses, decisions, risks and next actions; support final reporting and lessons learned.


Qualifications

Required / Minimum Qualifications

  • A relevant degree in Computer Science, Computer Security, Statistics, Mathematics or a related field, or equivalent practical experience in cybersecurity, incident management or related operations, AND 5+ years of industry experience.
  • Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions.
  • Ability to correlate and assess evidence from multiple sources, reconstruct incident timelines, evaluate compromise scope and possible exfiltration, and clearly explain findings and uncertainty.
  • Experience directing response activities while balancing rapid recovery, technical dependencies and business impact.
  • Demonstrated ability to lead technical specialists and stakeholders, identify engagement gaps, request appropriate resources and manage investigations using a global follow-the-sun model.
  • Demonstrable customer-facing written and verbal communication, including executive briefings.
  • Flexibility to work non-standard business hours that may include evening, nighttime, weekends, and/or holidays.

Preferred Qualifications

  • Experience analysing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations.
  • Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability.
  • Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information.

Citizenship & Citizenship Verification

This position requires verification of Australian citizenship due to citizenship-based legal restrictions. Specifically, this position supports Australian government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport.

Security Clearance Requirements

Ability to meet Microsoft, customer and / or government security screening requirements are required for this role.  These requirements include but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.

#DART


This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.




Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Others jobs →

AI Response Evaluator

Freelance France, Japan, Mexico +3 more $10K – $20K Others

Surgical & Clinical Care Coordinator - CPT & Authorization Specialist

Full Time Philippines Others

Client Scheduling & Intake Specialist

Full Time Philippines Others

Senior Software Developer

Full Time Brazil Others

Staff Research Engineer - AI & Machine Learning

Full Time United States Others

Customer Service Representative - Nicaragua

Full Time Nicaragua Others
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 219,313+ Jobs in Others

Answer easy questions

Answer easy questions

219,313+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified