Cybersecurity Threat Hunter and Forensic Analyst

at  Microsoft

Singapore, Southeast, Singapore -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate08 Nov, 2024Not Specified09 Aug, 20242 year(s) or aboveBriefing,Excel,Citizenship,Blogs,Microsoft,Firewall,Modeling,Technical Writing,Antivirus,Regulations,Linux,Color,Forensics,Computer Science,Anomaly Detection,Malware Analysis,Threat Intelligence,Presentation Skills,Idps,Windows,Presentations,EthnicityNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

With over 18,000 employees worldwide, the Microsoft Customer Experience & Success (CE&S) organization is responsible for the strategy, design, and implementation of Microsoft’s end-to-end customer experience. Come join CE&S and help us build a future where customers come to us not only because we provide industry-leading products and services, but also because we provide a differentiated and connected customer experience.
The Global Customer Success (GCS) organization is leading the effort to create the desired customer experience through support offer creation, driving digital transformation across our tools, and delivering operational excellence across CE&S.
The Microsoft Detection and Response team (DART) is hiring for a Cybersecurity Threat Hunter and Forensic Analyst. This position will be a vital individual contributor role on the DART Team in taking the lead in threat hunting and forensics in delivery of cybersecurity investigations for our customers. You will work in a fast-paced, intellectually intense, service-oriented environment where collaboration and speed are key to our investigations.
This role is flexible in that you can work up to 100% from home.
Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

REQUIRED/MINIMUM QUALIFICATIONS

  • 5+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection

  • OR Master’s Degree in Statistics, Mathematics, Computer Science or related field

  • In-depth knowledge of one or more of the following disciplines:

  • Windows forensics and an understanding of how to leverage forensic artifacts (Event Logs, Prefetch, Shimcache, Amcache, ShellBags, etc.) to answer key investigative questions- Knowledge of Windows memory forensics, Linux, and/or macOS forensics is a plus- Cloud forensics, and the ability to investigate security incidents using the Microsoft product stack- Experience investigating identity-based attacks- Knowledge of third-party cloud providers such as AWS, GCP, etc. is a plus- Threat Hunting, and taking a proactive approach to identifying threats- Knowledge of threat actor tactics, techniques, and procedures (TTPs)- Ability to identify anomalies in a given dataset- Ability to correlate data from disparate data sources

  • Attention to detail and an investigative mindset

  • Ability to contextualize and prioritize findings to put together a comprehensive account and briefing of the events that transpired during a security incident

  • Advanced technical writing and storytelling skills. Able to pull together multiple disparate events to build and communicate a cohesive timeline of activity.

  • Champion of continuous documentation of technical findings and ongoing investigation threads for fellow team members and key external stakeholders
  • Excellent written and oral presentation skills, with the ability to convey complex topics to non-technical audiences
  • Understanding of security products within an IT environment in multiple layers of the security stack (Antivirus, EDR, IDPS, proxy, firewall, VPN, email, etc.)
  • Advanced usage of Microsoft Office, specifically PowerPoint, Excel, and Word

Additional or Preferred Qualifications

  • 6+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection

  • OR Doctorate in Statistics, Mathematics, Computer Science or related field

  • Coding/scripting experience

  • Experience with third-party security products, including but not limited to, Splunk, CrowdStrike Falcon, QRadar, etc.
  • Experience with Kusto Query Language (KQL)
  • Familiarity with MITRE ATT&CK framework
  • Experience with malware analysis
  • Experience with the intelligence cycle, and generating threat intelligence from investigative findings
  • Experience performing large scale investigations of advanced adversaries
  • Published research (blogs, presentations, etc) on novel threat actor TTPs
  • Mentorship of junior investigators

Ability to meet Microsoft, customer and / or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.
Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations

Responsibilities:


REQUIREMENT SUMMARY

Min:2.0Max:7.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Other

Graduate

Computer Science, Mathematics, Statistics

Proficient

1

Singapore, Singapore