We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Security Incident Commander

Microsoft
United States, Washington, Redmond
Dec 18, 2024
OverviewSecurity is the foremost concern for Microsoft and our customers in a world increasingly challenged by digital threats, regulatory demands, and estate complexity. The Microsoft Security organization accelerates Microsoft's mission to ensure that our company and industry effectively secure digital technology platforms, devices, and clouds across our customers' diverse environments, as well as our own internal systems. Within Microsoft Security, the CISO organization is dedicated to defending the Microsoft estate and protecting our customers and partners who rely on it with our approach reinforced by the Microsoft Secure Future Initiative (SFI), a company wide effort to evolve how we design, build, test, and operate our products and services to achieve the highest possible standards for security. Our strategy is anchored in stopping adversaries through the integration of advanced threat intelligence, proactive threat hunting, rock solid operations, sustainable governance, and the facilitation of automation and augmentation with AI to anticipate, detect, and neutralize even the most sophisticated attacks. We cultivate a culture focused on growth, excellence, and empowering our teams and leaders to perform at their highest level, leading to innovations that impact billions of lives around the world. We are seeking an Security Incident Commander to manage cybersecurity incidents driven by Microsoft's Cyber Defense Operations - Operations Hub. The Operations Hub is the centerpiece of the Defense Operations organization and is responsible for cybersecurity incident coordination, cross-organizational communications, oversight and monitoring across Defense Operations, and continuous improvement of Defense Operations processes. With the continued evolution of the external threat landscape, Microsoft continues to be a prime target for a variety of threat actors and experiences an increasing number of attempts to breach its defenses. In this role, you will lead cross-functional incident response coordination for high complexity and large-scale security events. You will be ensuring incidents are managed effectively, by tracking the progress of incident response activities so that response efforts move at pace with clear milestones defined, and risk and progress is communicated accurately to all relevant stakeholders. Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
ResponsibilitiesIn this role, you will also handle communications in a timely manner with clear ownership and resolution and to drive continuous improvement to ensure our Cyber Defense Operation function remains agile, efficient, and at the cutting edge of threats and challenges. Core Responsibilities: Continuously identify and engage the appropriate stakeholders throughout the entirety of a security incident and ensure stakeholder teams are operating according to their Service-Level Agreements (SLAs). Facilitate or escalate decisions and critical blockers to leadership throughout the response, as needed to ensure that the security incident response is moving forward with appropriate pace Maintain the general response timeline and facts of the security incident throughout response events. Assess escalated cases to confirm an incident's severity, risk, and impact using details outlined in established procedures. Activate the incident response process outlined in formal procedures when the criteria are met. Lead Security Incident Response Team meetings per the procedures outlined in formal playbooks. Determine when and how to de-escalate the response by using the processes defined in formal documentation. Participate in the development and implementation of standardized procedures for coordinating large-scale adversary cybersecurity. Build strong partnerships across defense, engineering, governance, compliance and security teams to enable timely incident coordination. Participate in the creation of metrics and reporting to measure the effectiveness of incident coordination, identifying and addressing gaps or inefficiencies. Participate process improvements, best practices, and automation opportunities to enhance the methods by which incidents are coordinated and related information is communicated across the organization. Ensure alignment with broader cybersecurity strategies, compliance requirements, and industry standards.
Applied = 0

(web-776696b8bf-vd2jz)