New job, posted less than a week ago!
Job Details
Posted date: Sep 24, 2026
Category: Security Research
Location: Multiple Locations, Multiple Locations
Estimated salary: $45,000
Range: $45,000 - $45,000
Employment type: Full-Time
Travel amount: 25.0%
Work location type: 0 days / week in-office – remote
Role: Individual Contributor
Description
OverviewWith more than 45,000 employees and partners worldwide, the Customer Experience and Success (CE&S) organization is on a mission to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft's products and services, ignited by our people and culture. We drive cross-company alignment and execution, ensuring that we consistently exceed customers' expectations in every interaction, whether in-product, digital, or human-centered. CE&S is responsible for all up services across the company, including consulting, customer success, and support across Microsoft's portfolio of solutions and products. Join CE&S and help us accelerate AI transformation for our customers and the world.
Microsoft's Detection and Response Team (DART) is seeking a skilled and experienced Cybersecurity Lead Investigator to join the team in Australia. DART is the first port of call for many customers during a security incident. This pivotal, customer-facing role calls for a technically deep and agile investigator who can lead complex, high-impact incident response across on-premises and cloud environments and turn incomplete evidence into clear, defensible response decisions.
You will lead the investigation, establish technical priorities and act as the primary technical point of contact for customers, including executive stakeholders. Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. Incident coordinators support staffing, scheduling and operational escalation; the Lead Investigator owns investigation direction and technical judgement within the agreed engagement scope.
As part of a globally distributed, mission-driven team, you will share research, mentor colleagues and help shape the future of Defender Experts Cybersecurity Incident Response. Microsoft's mission is to empower every person and every organization on the planet to achieve more. Employees are expected to demonstrate a growth mindset, innovation, collaboration, respect, integrity, accountability, and inclusion.
Responsibilities
As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers.
Set investigation objectives, hypotheses, priorities and evidence requirements; lead hands-on analysis and specialist workstreams across enterprise on-premises and cloud environments.Contextualise and prioritise findings, correlate disparate evidence and build cohesive incident timelines. Establish what is known, what remains uncertain and what additional collection or analysis is needed.Assess adversary activity, compromise scope and potential data collection or exfiltration; validate key findings and explain the confidence and limitations of conclusions.Direct technical response planning and recommendations to secure enterprise environments, balancing containment and recovery urgency with evidence preservation and customer business constraints. Coordinate execution with customer-authorised teams and relevant specialists.Serve as the primary technical point of contact for complex investigations; brief technical teams, executives, legal, compliance, engineering and other stakeholders with clear objectives, findings and decision options.Identify skill, access, telemetry and resource gaps early; work with incident coordinators and leadership to resolve dependencies, obtain specialist support and escalate delivery risks.Maintain investigative documentation and clear follow-the-sun handovers covering evidence, hypotheses, decisions, risks and next actions; support final reporting and lessons learned.
Qualifications
Required / Minimum QualificationsA relevant degree in Computer Science, Computer Security, Statistics, Mathematics or a related field, or equivalent practical experience in cybersecurity, incident management or related operations, AND 5+ years of industry experience.Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions.Ability to correlate and assess evidence from multiple sources, reconstruct incident timelines, evaluate compromise scope and possible exfiltration, and clearly explain findings and uncertainty.Experience directing response activities while balancing rapid recovery, technical dependencies and business impact.Demonstrated ability to lead technical specialists and stakeholders, identify engagement gaps, request appropriate resources and manage investigations using a global follow-the-sun model.Demonstrable customer-facing written and verbal communication, including executive briefings.Flexibility to work non-standard business hours that may include evening, nighttime, weekends, and/or holidays.Preferred QualificationsExperience analysing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations.Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability.Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information.Citizenship & Citizenship VerificationThis position requires verification of Australian citizenship due to citizenship-based legal restrictions. Specifically, this position supports Australian government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport.
Security Clearance RequirementsAbility to meet Microsoft, customer and / or government security screening requirements are required for this role. These requirements include but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.
#DART
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.