25 Sep
|
Microsoft
|
Australia
25 Sep
Microsoft
Australia
Working with threat hunters, reverse engineers, infrastructure engineers and incident coordinators, you will bring together investigative findings, and direct response recommendations, balancing investigation with rapid recovery and containment. As a Lead Investigator, you will orchestrate evidence-driven investigations and technical incident response, align specialist workstreams and communicate clear findings, priorities and recommendations to customers. Set investigation objectives, hypotheses, priorities and evidence requirements; lead hands-on analysis and specialist workstreams across enterprise on-premises and cloud environments. Contextualise and prioritise findings, correlate disparate evidence and build cohesive incident timelines. Establish what is known, what remains uncertain and what additional collection or analysis is needed. Assess adversary activity, compromise scope and potential data collection or exfiltration; validate key findings and explain the confidence and limitations of conclusions. Direct technical response planning and recommendations to secure enterprise environments, balancing containment and recovery urgency with evidence preservation and customer business constraints. Coordinate execution with customer-authorised teams and relevant specialists. Serve as the primary technical point of contact for complex investigations; brief technical teams, executives, legal, compliance, engineering and other stakeholders with transparent objectives, findings and decision options. Identify skill, access, telemetry and resource gaps early; work with incident coordinators and leadership to resolve dependencies, obtain specialist support and escalate delivery risks. Maintain investigative documentation and clear follow-the-sun handovers covering evidence, hypotheses, decisions,
risks and next actions; support final reporting and lessons learned. A relevant degree in Computer Science, Computer Security, Statistics, Mathematics or a related field, or equivalent practical experience in cybersecurity, incident management or related operations, AND 5+ years of industry experience. Demonstrated hands-on experience leading large-scale, high-pressure cybersecurity incident response across on-premises and cloud environments, including setting investigation direction and guiding evidence-driven customer decisions. Ability to correlate and assess evidence from multiple sources, reconstruct incident timelines, evaluate compromise scope and possible exfiltration, and clearly explain findings and uncertainty. Experience directing response activities while balancing rapid recovery, technical dependencies and business impact. Demonstrated ability to lead technical specialists and stakeholders, identify engagement gaps, request appropriate resources and manage investigations using a global follow-the-sun model. Demonstrable customer-facing written and verbal communication, including executive briefings. Flexibility to work non-standard business hours that may include evening, nighttime, weekends, and/or holidays. Experience analysing nation-state or cybercrime activity and applying adversary knowledge to complex enterprise investigations. Demonstrated research, analytical automation, data-quality improvement and technical mentoring that strengthen investigation capability. Experience developing reviewed technical publications, presentations or other knowledge-sharing material while protecting sensitive information. DART This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. *
📌 Cybersecurity Lead Investigator (Australia)
🏢 Microsoft
📍 Australia