Cybersecurity Threat Hunter and Forensic Analyst
at Microsoft
Singapore, Southeast, Singapore -
Start Date | Expiry Date | Salary | Posted On | Experience | Skills | Telecommute | Sponsor Visa |
---|---|---|---|---|---|---|---|
Immediate | 08 Nov, 2024 | Not Specified | 09 Aug, 2024 | 2 year(s) or above | Briefing,Excel,Citizenship,Blogs,Microsoft,Firewall,Modeling,Technical Writing,Antivirus,Regulations,Linux,Color,Forensics,Computer Science,Anomaly Detection,Malware Analysis,Threat Intelligence,Presentation Skills,Idps,Windows,Presentations,Ethnicity | No | No |
Required Visa Status:
Citizen | GC |
US Citizen | Student Visa |
H1B | CPT |
OPT | H4 Spouse of H1B |
GC Green Card |
Employment Type:
Full Time | Part Time |
Permanent | Independent - 1099 |
Contract – W2 | C2H Independent |
C2H W2 | Contract – Corp 2 Corp |
Contract to Hire – Corp 2 Corp |
Description:
With over 18,000 employees worldwide, the Microsoft Customer Experience & Success (CE&S) organization is responsible for the strategy, design, and implementation of Microsoft’s end-to-end customer experience. Come join CE&S and help us build a future where customers come to us not only because we provide industry-leading products and services, but also because we provide a differentiated and connected customer experience.
The Global Customer Success (GCS) organization is leading the effort to create the desired customer experience through support offer creation, driving digital transformation across our tools, and delivering operational excellence across CE&S.
The Microsoft Detection and Response team (DART) is hiring for a Cybersecurity Threat Hunter and Forensic Analyst. This position will be a vital individual contributor role on the DART Team in taking the lead in threat hunting and forensics in delivery of cybersecurity investigations for our customers. You will work in a fast-paced, intellectually intense, service-oriented environment where collaboration and speed are key to our investigations.
This role is flexible in that you can work up to 100% from home.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
REQUIRED/MINIMUM QUALIFICATIONS
5+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
OR Master’s Degree in Statistics, Mathematics, Computer Science or related field
In-depth knowledge of one or more of the following disciplines:
Windows forensics and an understanding of how to leverage forensic artifacts (Event Logs, Prefetch, Shimcache, Amcache, ShellBags, etc.) to answer key investigative questions- Knowledge of Windows memory forensics, Linux, and/or macOS forensics is a plus- Cloud forensics, and the ability to investigate security incidents using the Microsoft product stack- Experience investigating identity-based attacks- Knowledge of third-party cloud providers such as AWS, GCP, etc. is a plus- Threat Hunting, and taking a proactive approach to identifying threats- Knowledge of threat actor tactics, techniques, and procedures (TTPs)- Ability to identify anomalies in a given dataset- Ability to correlate data from disparate data sources
Attention to detail and an investigative mindset
Ability to contextualize and prioritize findings to put together a comprehensive account and briefing of the events that transpired during a security incident
Advanced technical writing and storytelling skills. Able to pull together multiple disparate events to build and communicate a cohesive timeline of activity.
- Champion of continuous documentation of technical findings and ongoing investigation threads for fellow team members and key external stakeholders
- Excellent written and oral presentation skills, with the ability to convey complex topics to non-technical audiences
- Understanding of security products within an IT environment in multiple layers of the security stack (Antivirus, EDR, IDPS, proxy, firewall, VPN, email, etc.)
- Advanced usage of Microsoft Office, specifically PowerPoint, Excel, and Word
Additional or Preferred Qualifications
6+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection
OR Doctorate in Statistics, Mathematics, Computer Science or related field
Coding/scripting experience
- Experience with third-party security products, including but not limited to, Splunk, CrowdStrike Falcon, QRadar, etc.
- Experience with Kusto Query Language (KQL)
- Familiarity with MITRE ATT&CK framework
- Experience with malware analysis
- Experience with the intelligence cycle, and generating threat intelligence from investigative findings
- Experience performing large scale investigations of advanced adversaries
- Published research (blogs, presentations, etc) on novel threat actor TTPs
- Mentorship of junior investigators
Ability to meet Microsoft, customer and / or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.
Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations
Responsibilities:
REQUIREMENT SUMMARY
Min:2.0Max:7.0 year(s)
Information Technology/IT
IT Software - Network Administration / Security
Other
Graduate
Computer Science, Mathematics, Statistics
Proficient
1
Singapore, Singapore