Security Operations Engineer - CTJ - Poly
What you'll need to apply
Fields this application requires
Company-specific questions
- Is your legal name the same as your preferred name?
- Address
- Country/region of residence
- State
- Postal Code/Zip
- Ethnicity/Race
- Gender
- U.S. Armed Forces Status
- Veteran Status
- Are you currently or have you ever been a member of the military, a civilian employee, or an official of any government, whether national, state, local, or foreign?
- Have you signed a non-compete or non-disclosure statement which may become an obstacle to your acceptance at Microsoft?
- Have you ever worked with Microsoft as a full-time / part-time employee, intern, vendor, agency temporary, or business guest? If yes, please provide as much information about your former employment as you can.
- Are you currently employed by a Microsoft subsidiary (e.g., LinkedIn, GitHub, Gaming Studios, Activision, Blizzard, King)?
- As part of the online application process you were asked whether you possess certain minimum required qualifications for the role to which you are applying. By selecting yes, you agree that you answered these questions accurately. You further acknowledge that your answers may result in your application not being considered further for this role if you do not currently meet the required qualifications for the role.
- By checking this you agree to the Microsoft Data Privacy Notice (DPN) .
- By checking this, you affirm that you have familiarized yourself with the Microsoft recruiting process and agree to the candidate code of conduct .
About this role
Employer-provided description, formatted for easier reading.
Overview Join the Microsoft Specialized Cloud (MSC) team as a Security Operations Engineer , where engineers build and operate highly secure cloud platforms, services, and developer experiences that support mission-critical workloads for U. S. Government customers.
MSC software engineering teams design, develop, and evolve technologies that enable customers to operate at scale while meeting specialized security, compliance, and operational requirements. Drawing on expertise across distributed systems, cloud infrastructure, data, reliability, performance, and developer productivity, engineers collaborate across Microsoft to deliver trusted, resilient, and innovative solutions.
Working in Microsoft Specialized Clouds offers unique opportunities to solve technical challenges not commonly found in commercial cloud environments. Engineers build software for highly regulated and security-sensitive scenarios, develop solutions that operate in specialized and restricted environments, and help shape cloud technologies that support critical government missions and services.
We welcome engineers with diverse experiences, perspectives, and approaches to problem solving. We believe innovation is strengthened through inclusion and are committed to creating an environment where individuals can learn, grow, and contribute meaningfully. Whether your experience comes from industry, research, open-source projects, military service, technical training, or other pathways, we encourage you to apply.
At Microsoft, our mission—to empower every person and every organization on the planet to achieve more—guides how we partner with customers to deliver trusted, impactful solutions. With a growth mindset culture, we innovate responsibly and measure success by shared progress—people, teams, and customers. Join us to do meaningful work that changes the world and helps shape what’s next for everyone.
Responsibilities
- Lead Authorization & Accreditation (A&A) activities for Microsoft cloud platform services, driving successful Authority to Operate (ATO) outcomes across government and regulated environments.
- Develop, maintain, and oversee all Risk Management Framework (RMF) documentation and security artifacts, including SSPs, SAPs, SARs, POA&Ms, control implementations, and continuous monitoring evidence.
- Plan, coordinate, and execute government compliance assessments, independent audits, inspections, and penetration testing activities, ensuring timely remediation of findings and sustained authorization status.
- Serve as the primary security liaison with government accrediting officials, auditors, and internal stakeholders, providing guidance on compliance requirements and risk management strategies.
- Negotiate and resolve complex security, compliance, and accreditation issues with leadership teams, customers, and external oversight organizations while balancing mission, risk, and operational objectives.
- Provide deep technical expertise in Microsoft Azure services, cloud architecture, security controls, networking, identity management, and platform operations within highly regulated environments.
- Perform secure administration and operational support of Azure environments, including implementation of security controls, monitoring, incident response, vulnerability management, and compliance-driven cloud operations; experience developing security automation and orchestration solutions is highly desirable.
Required Qualifications
- Doctorate in Statistics, Mathematics, Computer Science, or related field
- OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
- OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response
- OR equivalent experience.
Other Requirements:
- Security Clearance Requirements: Candidates must be able to meet Microsoft, customer and/or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings:
- The successful candidate must have an active U.S. Government Top Secret Clearance with access to Sensitive Compartmented Information (SCI) based on a Single Scope Background Investigation (SSBI) with Polygraph . Ability to meet Microsoft, customer and/or government security screening requirements are required pre-offer and post-hire for this role. Failure to maintain or obtain the appropriate U.S. Government clearance and/or customer screening requirements may result in employment action up to and including termination.
- Clearance Verification : This position requires successful verification of the stated security clearance to meet federal government customer requirements. You will be asked to provide clearance verification information prior to an offer of employment.
- Microsoft Cloud Background Check : This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.
Citizenship & Citizenship Verification
This position requires verification of U. S. citizenship due to citizenship-based legal restrictions.
Specifically, this position supports United States federal, state, and/or local United States government agency customer and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government Clearance .
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Computer or Software Engineering, Information Systems, or a related field
- OR equivalent practical experience.
- 7+ years of experience in a customer-facing technical security role, including leadership of high-severity product or service incidents, crisis situations, or complex technical escalations.
- Ability to diagnose and scope complex technical issues across enterprise security environments, including interpreting logs and telemetry, assessing product behavior, and reasoning across identity, endpoint, network, and cloud architecture to validate customer impact and engage the right engineering teams.
- General working knowledge of Microsoft Azure Security solutions (Purview, Defender, Entra, Intune, or Sentinel) sufficient to advise customers on capabilities, architecture, implementation, and operational considerations.
- Professional proficiency in written and spoken English sufficient to translate complex technical issues into clear business impacts and communicate effectively with customers, engineers, product teams, and executive stakeholders.
- Advanced degree (such as a Master's or PhD) in Cybersecurity, Computer Science, Computer or Software Engineering, Information Systems, or a related field, or demonstrated advanced specialization through substantial technical leadership, applied research, or recognized professional expertise.
- Demonstrated use of Microsoft Copilot or other generative AI technologies to improve operational efficiency, scalability, and customer outcomes.
- Proven ability to develop service improvement plans, conduct customer health reviews, analyze operational signals, or create technical readiness content.
- Applied knowledge of regulatory compliance and enterprise risk management frameworks, combined with IT Service Managemen