Source description
About the role
Lead the Prague CZ operations team responsible for customer-facing detection, investigation, threat hunting, and response support for Defender Experts for XDR. Coach security analysts by defining clear objectives and outcomes, connecting work to customer and business impact, giving timely feedback, removing blockers, and helping employees build durable security operations capability. Care for employees by creating an environment where people feel valued, respected, included, and supported in their wellbeing, career growth, and aspirations. Establish and manage the local operating rhythm for quality, coverage, onboarding, training, case review, escalation, customer readiness, and cross-time-zone handoffs. Ensure the team delivers high-quality proactive and reactive threat hunting, investigation, and response outcomes across customer environments. Partner with threat research, data science, engineering, and global operations teams to improve detections, service quality, tooling, triage workflows, and operational readiness. Drive adoption of AI-powered security tools, copilot, and agentic workflows that accelerate investigations, enrich customer findings, improve analytical efficiency, and reduce repetitive operational burden. Sponsor and operationalize AI agents and automations that assist with case enrichment, investigation summarization, detection validation, quality review, onboarding, reporting, and customer-ready outputs. Use metrics, customer feedback, quality reviews, and operational signals to identify systemic improvements and translate them into durable processes, training, automation, or product feedback. Build a healthy, resilient team culture that supports learning, experimentation, knowledge sharing, and continuous improvement while maintaining high standards for customer impact. Participate in a global security operations model, including potential weekend, holiday, or non-standard business-hour coverage where legally allowed and aligned to local requirements. Experience in Security Operations, Threat Intelligence, Cyber Incident Response, Penetration Testing/Red Team, Detection Engineering, or related cybersecurity operations roles. People management, team leadership, service delivery leadership, or demonstrated experience coaching technical teams toward operational outcomes. Experience leading customer-facing or service-delivery security operations where quality, timeliness, communication, and customer outcomes are critical. Ability to work from the Prague office at least three (3) days per week. Ability to support weekend, holiday, and non-standard business-hour coverage where legally allowed and aligned to local labor regulations. Experience building, leading, or scaling a new site, shift, region, operations team, or service-delivery capability preferred. Experience leveraging generative AI, large language models, copilots, autonomous agents, or AI-assisted workflows to improve security operations, threat hunting, incident response, investigations, reporting, quality review, or operational efficiency. Experience sponsoring or building automations or AI-assisted workflows using scripting languages, orchestration platforms, low-code automation tools, or agent frameworks. Knowledge of kill-chain model, MITRE ATT&CK framework, modern penetration testing techniques, cloud security, identity security, and operating system internals. Experience with threat intelligence curation, customer briefings, incident response, DFIR, detection engineering, or offensive security techniques. Excellent cross-group collaboration and communication skills, including the ability to influence across operations, research, engineering, and business stakeholders. Strong ability to use data to tell a story, identify systemic improvement opportunities, and drive clear prioritization. Additional advanced technical degrees or cyber security certifications such as CISSP, OSCP, CEH, GIAC, or equivalent experience preferred.
More at Microsoft
Related open roles
Program Manager, Global Security Access Management (GSAM)
Seattle · Onsite
Principal Technical Advisor for Cybersecurity Incident Response
Seattle · Dallas–Fort Worth · Onsite
Senior Security Researcher
Seattle · Washington DC · Onsite
Security Engineer
London · Dublin · Onsite
Security Cloud Solution Architect- CTJ - Poly
Washington DC · Onsite
Senior Cloud Solution Architect - Security / Global Solutions
Tokyo · Onsite