Senior Cybersecurity Incident Coordinator
With more than 45,000 employees and partners worldwide, the Customer Experience and Success (CE&S) organization is on a mission to empower customers to accelerate business value through differentiated customer experiences that leverage Microsoft's products and services, ignited by our people and culture. We drive cross-company alignment and execution, ensuring that we consistently exceed customers' expectations in every interaction, whether in-product, digital, or human-centered. CE&S is responsible for all up services across the company, including consulting, customer success, and support across Microsoft's portfolio of solutions and products. Join CE&S and help us accelerate AI transformation for our customers and the world.
Microsoft's Detection and Response Team (DART) is seeking a skilled and experienced Senior Cybersecurity Incident Coordinator to join the team. DART is the first port of call for many customers during a security incident. This pivotal, customer-facing position calls for an agile operational leader who can coordinate complex cybersecurity incidents, align stakeholders and ensure effective staffing and delivery of proactive and reactive engagements.
The successful candidate will combine deep cybersecurity fluency with sound judgement, clear communication and disciplined operational management. As part of a globally distributed, mission-driven team, you will work alongside investigation leads, threat hunters, reverse engineers and infrastructure engineers, helping shape the future of Defender Experts Cybersecurity Incident Response.
Microsoft's mission is to empower every person and every organization on the planet to achieve more. Employees are expected to demonstrate a growth mindset, innovation, collaboration, respect, integrity, accountability, and inclusion.
Responsibilities
As a Senior Cybersecurity Incident Coordinator, you will independently coordinate customer engagements and concurrent operational workstreams, keep stakeholders aligned, and enable technical specialists to deliver effective response outcomes.
Operational Management
- Coordinate intake and pre-engagement scoping with customers and technical leads: clarify needs, desired outcomes, dependencies, resource requirements and delivery timelines.
- Manage engagement staffing and capacity, including special-event support, matching available skills to demand and escalating resource gaps or conflicting priorities.
- Maintain escalation pathways, direct issues to the appropriate delivery teams, track progress and promptly raise urgent, sensitive or unresolved matters to leadership.
- Serve as an operational point of coordination for customers, technical teams, executives, consultants and partners; communicate priorities, decisions, dependencies and next steps clearly.
- Coordinate multiple concurrent engagements and workstreams, prioritise and delegate operational tasks, and maintain accurate status, schedules, risks, decisions and action records.
- Lead daily and weekly operational standups and status reporting, follow through on agreed actions, and provide clear follow-the-sun handovers with explicit ownership and outstanding risks.
- Partner with technical leads to translate investigation findings and uncertainty into clear customer updates. Coordinate dependencies for evidence preservation, containment and recovery while leaving technical decisions and execution with the responsible specialists.
- Collaborate with Legal, Security Research, Product Groups and other internal teams to address emerging issues and remove delivery blockers.
- Maintain and improve incident management procedures and operational workflows; identify demand trends and recurring bottlenecks, and use lessons learned to improve delivery.
Required / Minimum Qualifications
- A relevant degree in Computer Science, Computer Security, Statistics, Mathematics or a related field, or equivalent practical experience in cybersecurity, incident management or related operations AND 5+ years of industry experience
- Demonstrated experience coordinating customer-facing cybersecurity incidents or complex security service delivery, including planning and stakeholder communications.
- Demonstrated ability to manage multiple concurrent workstreams, prioritise competing demands, delegate tasks and align resources and stakeholders under time pressure.
- Technical fluency in enterprise cybersecurity across endpoint, identity, cloud and network environments, sufficient to understand investigation findings, dependencies and uncertainty and communicate effectively with technical specialists and customers.
- Evidence of sound operational judgement, accurate record keeping, clear written and verbal communication, and effective follow-the-sun handovers.
- Flexibility to work shifts, including assignments during non-standard business hours that may include evening, nighttime, weekends, and/or holidays.
Preferred Qualifications
- Experience coordinating high-pressure incident response at enterprise scale, including executive communications, competing customer priorities and globally distributed teams.
- Experience in capacity planning, project management, process design and operational improvement, supported by relevant methodologies or frameworks.
- Familiarity with NIST CSF, MITRE ATT&CK, ISO 27001, and the dependencies between investigation, containment and recovery.
- Hands-on investigation, identity security, threat hunting, forensics, scripting, KQL or automation experience that strengthens coordination and operational efficiency; these are not mandatory entry requirements.
- Relevant security or incident/project management certifications, or equivalent practical expertise; demonstrated stakeholder influence, mentoring and resilience.
Citizenship & Citizenship Verification
This position requires verification of Australian citizenship due to citizenship-based legal restrictions. Specifically, this position supports Australian government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport.
Security Clearance Requirements
Ability to meet Microsoft, customer and / or government security screening requirements are required for this role. These requirements include, but are not limited to the following specialized security screenings: Microsoft Cloud Background Check: This position will be required to pass the Microsoft Cloud Background Check upon hire / transfer and every two years thereafter.
#DART
This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.
Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.