New
Incident Response Manager
![]() | |
![]() United States, Washington, Redmond | |
![]() | |
OverviewThe Microsoft Customer and Partner Solutions (MCAPS) Division unifies the commercial go-to market organization to accelerate our progress, stay true to the Microsoft mission, and empower our customers, partners, people, and Microsoft's growth. Within MCAPS, TrIP (Trust and Integrity Protection) provides policies, guidance and oversight of risk & compliance across the MCAPS division for security, privacy, trade, anti-bribery resilience & incident response. The Trust and Integrity Protection (TrIP) team is looking for a motivated Incident Response Manager to be a part of the Incident Response (IR) Team. In this role you will have the opportunity to work on privacy, cybersecurity, and security issues as part of a dynamic and high-impact team. Your day-to-day responsibilities include conducting detailed and comprehensive investigations and driving issues to closure. You will analyze, contain, and mitigate escalations from multiple sources, both internal and external. You will also contribute to developing innovative automation, leveraging AI responsibly, and orchestration solutions for response. As part of the job, you will collaborate with incident response partners and Microsoft privacy groups to improve our security and privacy posture.
ResponsibilitiesIncident Response technical program managementConduct detailed comprehensive triage and investigation on a wide variety of privacy/security events and implement containment and mitigation processes.Collaborate with internal incident response partners to drive issue containment, remediation, management and closure.Contribute and/or Document standard operating procedures, playbooks that support IR scenarios within scope for the TrIP IR function.Detect and respond to threats, anomalous or suspicious activity, combined with intelligence, to identify potential and active risks to systems and data.Keep up to date with industry best practices and emerging vulnerability, response, mitigation, threat landscape trends and use this knowledge to drive proactive detection and issue avoidance.Ensure reliable and timely notification to impacted customers and/or regulators in accordance with appropriate regulations and contractual obligations.Conduct regular table-top/exercises and simulations with relevant parties and identify and remediate any gaps.OperationsLiaise with vendor teams to ensure smooth Tier 1 operation (intake) and Service Level Agreements (SLAs).Seek opportunities for automation and AI for process efficiencies, eliminating un-necessary workflows in Incident Response (IR).Use business intelligence to drive awareness, insights and trends and identify systemic and emerging themes to improve the overall security and privacy posture.Risk and CompliancePartner with security and privacy risk managers on risk identification and documentation, controls identification and monitoring that ensures shift left in development practices.Work with analysts and engineers by observing gaps and opportunities to provide efficiencies in detection and response.We handle active security events and respond to threats from a variety of sources; you will be required to participate in shift and on call rotation.Act as a trusted advisor and influence engineering and business partners to adopt best practices, consult, ensure risks are logged, remediations are implemented to reduce security and privacy risk in the division. |