About this role
<b>Overview</b><br><p>Microsoft Specialized Clouds (MSC) is seeking a Senior Cloud Network Security Engineer to design, deploy, and operate network security monitoring capabilities supporting sovereign and government cloud environments. This role focuses on network security telemetry, threat detection, alerting, automation, and operational ownership of critical security services.</p><p> </p><p>The Engineer will be responsible for deploying and configuring network security platforms, building telemetry pipelines, developing detections and alerts, and enabling visibility into network activity across cloud and hybrid environments. The role requires strong network security expertise, experience analyzing packet captures and network telemetry, and the ability to leverage automation and AI to improve monitoring, incident response, and operational efficiency.</p><p><br>As the Directly Responsible Individual (DRI) for assigned services, this engineer will provide operational ownership, incident leadership, and participation in on-call rotations to ensure service reliability, security visibility, and compliance readiness across Microsoft sovereign cloud offerings.</p><p> </p><p>Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond</p><br><br><b>Responsibilities</b><br><ul><li>Design, deploy, and manage network security platforms including firewalls, proxies, and traffic inspection solutions supporting sovereign cloud environments.</li><li>Configure network security devices to export logs, flow records, packet telemetry, and security events to centralized monitoring, analytics, and incident response platforms.</li><li>Develop and maintain network security detections, alerts, and analytics to identify malicious activity, unauthorized access, policy violations, and emerging threats.</li><li>Analyze packet captures, firewall logs, flow data, and network telemetry to support threat investigations, incident response, root cause analysis, and service improvements.</li><li>Build and maintain security telemetry pipelines that provide actionable visibility across network infrastructure, cloud services, and security platforms.</li><li>Develop automation solutions using scripting, Infrastructure as Code, and AI-enabled capabilities to improve detection engineering, alert correlation, incident triage, and operational efficiency.</li><li>Integrate network security telemetry, observability, and incident management platforms to improve monitoring coverage and response effectiveness.</li><li>Create operational dashboards, reporting, and health metrics to measure detection coverage, alert quality, service reliability, compliance posture, and operational risk.</li><li>Partner with engineering, security, and operations teams to define secure network architectures, monitoring standards, deployment patterns, and onboarding requirements for new services. </li></ul><p> </p><p><strong>Other</strong></p><ul><li>Embody our company <a title="" href="Culture%20%7C%20Microsoft%20Careers" target="_self">Culture</a> & <a title="" href="Our%20Mission%20and%20Values%20%7C%20About%20Microsoft" target="_self">Values</a></li></ul><br><br><b>Qualifications</b><br><div><strong>Required Qualifications:</strong></div><ul><li>Doctorate in Statistics, Mathematics, Computer Science, or related field<ul><li>OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology</li><li>OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology</li><li>OR equivalent experience.</li></ul></li></ul><p> </p><p><strong>Other Requirements:<br><br></strong></p><ul><li><strong>Microsoft Cloud Background Check: </strong>This position will be required to pass the Microsoft Cloud background check upon hire/transfer and every two years thereafter.</li><li><strong>Citizenship & Citizenship Verification</strong>: This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local [or applicable country] government agency customers and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate’s citizenship will be verified via a valid passport.</li></ul><p> </p><p><strong>Preferred Qualifications:</strong></p><ul><li>2+ years of experience using AI technologies to improve security operations, detection engineering, alert correlation, incident investigation, and operational workflows.</li><li>2+ years of experience supporting government, regulated, or sovereign cloud environments. </li><li>10+ years of experience designing, deploying, or operating network security infrastructure and services.</li><li>5+ years of experience with firewalls, DDoS protection, IDS/IPS platforms, proxies, traffic inspection, and network security controls.</li><li>5+ years of experience automating operational processes using Python, Terraform, Ansible, Bicep, ARM, or similar technologies.</li><li>3+ years of experience configuring security devices to export telemetry, logs, events, and flow data for centralized monitoring and threat analysis.</li><li>3+ years of experience developing security detections, alerting strategies, monitoring content, and operational response processes.</li><li>5+ years of experience supporting production services, incident response, operational ownership, and on-call rotations. </li></ul> <br><br><p>Security Operations Engineering IC4 - The typical base pay range for this role across the U.S. is USD $119,800 - $234,700 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $160,200 - $261,000 per year. </p><p></p> <p>Certain roles may be eligible for benefits and other compensation. Find additional benefits and pay information here:<br><a href="https://careers.microsoft.com/us/en/us-corporate-pay">https://careers.microsoft.com/us/en/us-corporate-pay</a></p><br><p>This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.</p><br><hr><br><p>Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about <a href="https://careers.microsoft.com/v2/global/en/accessibility.html"><b><u>requesting accommodations.</u></b></a></p>