Microsoft Senior Incident Response Engineer

New job, posted less than a week ago!

Job Details

Posted date: Jul 27, 2026

There have been 7 jobs posted with the title of Senior Incident Response Engineer all time at Microsoft.

Category: Technical Support Engineering

Location: Bucharest, Bucharest

Estimated salary: $300,650
Range: $45,000 - $556,300

Employment type: Full-Time

Work location type: 0 days / week in-office – remote

Role: Individual Contributor


Description

Overview

With more than 45,000 employees and partners worldwide, the Customer Experience and Success (CE&S) organization is on a mission to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft’s products and services, ignited by our people and culture. We drive cross-company alignment and execution, ensuring that we consistently exceed customers’ expectations in every interaction, whether in-product, digital, or human-centered. CE&S is responsible for all up services across the company, including consulting, customer success, and support across Microsoft’s portfolio of solutions and products. Join CE&S and help us accelerate AI transformation for our customers and the world.

Within CE&S, the Customer Service & Support (CSS) organization builds trust and confidence for every person and organization through delivering a seamless support experience. In CSS, we are powered by Microsoft’s AI technology to help consumers, businesses, partners, and more, resolve their issues quickly and securely, helping prevent future problems from occurring and achieving more from their Microsoft investment.

In the Customer Service & Support (CSS) team we are looking for people with a passion for delivering customer success. As a Senior Technical Support Engineer, you will own, troubleshoot, and solve highly complex customer technical issues. This opportunity will allow you to accelerate your career growth, hone your problem-solving, collaboration and research skills, and further deepen your technical proficiency – becoming a product expert.

Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.

Responsibilities

Responsibilities:

Scope customer security incidentsUnderstand and identify indicators of attack and indicators of compromiseAnalyse incident data from threat analytics toolsCollaborate with the Security and Threat Intelligence teams by providing indicators of compromise and samples of malware from the customer’s environmentCoordinate a response to the security incident with other Microsoft security and consulting teams.Develop, document, and implement runbooks, capabilities, and techniques for Incident ResponsePerform security triage and analysis on endpoint, server and network infrastructure.Perform activities necessary for immediate containment and short-term resolution of incidents.Maintain current knowledge and understanding of the threat landscape, emerging security threats, and vulnerabilitiesInvestigate root cause of complex security incidentsMaintain a high level of confidentialityParticipate in the on-call rotation as required

Qualifications

Required/Minimum Qualifications:

Candidate must have hands-on experience in customer-facing roles (Customer support experience is preferred).Experience in Cybersecurity and Security Incident Response.Ability to manage complex Incident Response situations with a focus on deep technical troubleshooting and empathetic customer engagement.Practical experience troubleshooting Network, Windows Server, Windows Client, and Active Directory environments.Working knowledge of Entra ID and Microsoft 365 management and troubleshooting experience.Experience supporting large and complex geographically distributed enterprise environments with 1000+ users.Bachelor's degree in Computer Science, Information Technology (IT), or related field AND demonstrated experience of technical support, technical consulting experience, or information technology experience.Additional or Preferred Qualifications:

Experience in Security Incident Response with recent operational security experience (Indicator of Attack / Indicator of Compromise deep investigation, On-Premises data and Cloud log investigation, Malware Analysis, Threat Analytics, Threat Intelligence, endpoint security, etc.)Experience in Network Security Administration, and/or Systems Administration with experience in Windows Server, Windows Client, and Active Directory AdministrationExperience in Cloud investigations with Entra ID, Microsoft 365 and Microsoft Defender solutionsExperience with any Microsoft Defender solutionsExperience in Azure Identity management and troubleshootingKusto Query Language knowledgeCloud experience with any of the major cloud providers, including cloud security, networking, and migration of multi-cloud or hybrid deploymentsAutomation (PowerShell and/or Python, Java, or a similar language, can be a beginner to intermediate level)Preferred IT Industry certifications (Microsoft Certifications On-Prem or Cloud, SANS GCIH, CISSP, CEH, Amazon AWS, etc.)

Language Qualification:

English Language: confident in reading, writing and speaking.

Ability to meet Microsoft, customer and / or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.

Technical Support Engineering IC5 - The typical base pay range for this role across Romania is lei 279,700.00 - lei 556,300.00 per year. Certain roles may be eligible for benefits and other compensation.

Find additional benefits and pay information here:

https://careers.microsoft.com/v2/global/en/corporate-pay/romania-corporate-pay.html

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.

Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.



Email job link for Senior Incident Response Engineer at Microsoft

Provide your email address to receive a message with the job link and details.

Check out other jobs at Microsoft.