Senior Incident Commander

Microsoft

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Salary
$119,800–$234,700 / yr
Posted
46 days ago
Freshness
Confirmed live yesterday
Closes
Jan 23, 2027

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $192k
This role $177k
$106k most similar roles pay here $249k

This role pays less than 57% of similar roles. Most pay $150,000–$234,825 — the shaded band above. At the midpoint, this role pays about $177k versus about $192k for comparable roles.

Based on 239 similar postings.

Employer

About Microsoft

Microsoft Corporation is a global technology leader producing software, hardware, and cloud services including Windows, Office 365, Azure cloud platform, Xbox gaming, and Surface devices. Industry: Software & Cloud Computing

Microsoft currently has 598 open roles on FindRole.

Listed pay typically runs $119,800–$234,700 across 586 roles with salary data.

Most-posted roles

View all roles at Microsoft

At a glance

TL;DR · Senior Incident Commander

As a Sr. Incident Commander within the Cyber Defense Operations Hub, you will join a dedicated security response team tasked with coordinating responses to critical security issues, including zero-day exploits and emerging threats against customers and internal infrastructure. You will perform cyber defense incident and vulnerability triage to determine scope and risk while making high-stakes decisions for rapid remediation. Your daily responsibilities include tracking incidents from escalation to resolution, providing tactical guidance to enterprise-wide defenders, and delivering executive updates regarding risks. You will also analyze threat landscapes to inform future investment areas. The role requires expertise in security incident and event management (SIEM), threat modeling, anomaly detection, and large-scale computing. Candidates should possess experience in information security incident handling, vulnerability triaging, and may hold certifications such as CISSP, CISA, CISM, SANS, OSCP, or Security+.

What you'll do

  • Triage cyber defense incidents and vulnerabilities to determine scope, urgency, and risk impact.
  • Make high-stakes decisions to ensure the rapid remediation of security risks for customers and Microsoft.
  • Track and document cyber defense incidents from initial escalation through final resolution.
  • Provide tactical security decisions and coordinate enterprise-wide defenders to resolve active incidents.
  • Deliver timely and clear executive updates regarding risks to customers and internal stakeholders.
  • Advise on and validate customer notifications and authoritative security guidance.
  • Analyze incident data to produce reports on threat trends and future investment areas.

What we're looking for

  • A Doctorate in Statistics, Mathematics, Computer Science, or a related field is required.
  • A Master's degree in a relevant field and 3+ years of experience in fields like cyber security or incident response is required.
  • A Bachelor's degree in a relevant field and 4+ years of experience in cyber security or incident response is required.
  • Candidates must be able to pass the Microsoft Cloud background check.
  • Candidates must provide proof of citizenship or U.S. permanent residency for export control and government contract requirements.
  • Relevant certifications such as CISSP, CISA, CISM, SANS, OSCP, or Security+ are preferred.
  • 5+ years of experience in information security incident handling and/or security operations is required.
  • 5+ years of experience triaging security vulnerabilities and driving product or service response is required.

More like this

Similar roles

Senior Incident Handler

Allstate

Remote (IL) 59 days ago $120,000$193,725
Incident Response EDR XDR SIEM Python PowerShell SOAR Malware Analysis Forensic Analysis Threat Hunting Network Security AI Scripting Cybersecurity Operations
5+ yrs exp Remote

Principal Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $182,200$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote

Principal Security Operations Engineering Manager

Microsoft

Redmond, WA +1 49 days ago $142,800$274,800
Azure Cybersecurity SIEM SOC Threat Modeling Anomaly Detection Incident Response Security Operations Data Analytics AI Software Development Lifecycle Large-scale Computing CISSP CISA CISM SANS OSCP Security+
6+ yrs exp

Principal Security Operations Engineer

Microsoft

Redmond, WA 13 days ago $142,800$274,800
Microsoft Sentinel KQL SIEM Incident Response Threat Modeling Anomaly Detection Cybersecurity Insider Threat LLM AI Post-Quantum Cryptography Purview DTEX Proofpoint ITM Magnet Axiom Forcepoint HPC
6+ yrs exp

Principal Security Architect

Microsoft

42 days ago $142,800$274,800
Identity Security Azure Security Operations SIEM Threat Modeling Authentication Authorization Cloud Security Anomaly Detection Incident Response cyber security
6+ yrs exp Hybrid

Senior & Principal Security Researcher

Microsoft

28 days ago $119,800$234,700
Threat Hunting Cybersecurity Kusto Query Language (KQL) SQL SIEM Jupyter Notebooks Forensics TTPs IOCs IOAs Vulnerability Research Anomaly Detection Software Development Lifecycle WinHex Encase FTK
4+ yrs exp