CrawlJobs Logo

M365 Incident Responder

https://www.citi.com/ Logo

Citi

Location Icon

Location:
United States, Irving

Category Icon
Category:
IT - Administration

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

125760.00 - 188640.00 USD / Year

Job Description:

Citi's Security Operations Center (SOC) Cloud Incident Response Team seeks a highly skilled and experienced M365 Incident Response practitioner to support critical efforts aimed at protecting Citi public cloud infrastructure, assets, clients and stakeholders. This is a demanding role with global exposure and responsibility. You will serve both as a technical subject matter expert and as an ambassador for the Cloud Incident Response team.

Job Responsibility:

  • Act as a subject matter expert on incident response for Entra ID and M365 set of services
  • Collaborate across teams to develop capabilities that support incident response and forensic analysis of M365 incidents
  • Designing, implementing, and participating in the incident response processes specific to Entra ID and M365 deployments
  • Develop, document and maintain operationally effective playbooks to deal with cloud based incidents
  • Collaborate with global multidisciplinary groups for triaging and defining the scope of large scale incidents
  • Document and present investigative findings for high profile events and other incidents of interest
  • Participate in readiness exercises such as purple team, table tops, etc.
  • Train junior colleagues on relevant best practices
  • Mitigate risk by analyzing the root cause of issues, impacts to business, and required corrective actions and develop security solutions
  • Provide Information Security advice and counsel as needed

Requirements:

  • Consistently demonstrates clear and concise written and verbal communication
  • Proven influencing and relationship management skills
  • Strong understanding of security incident response processes
  • Excellent technical documentation skills
  • Proven analytical skills
  • Knowledge of the tools and processes to provide operational security support to the Microsoft 365 (M365) ecosystem
  • Advanced proficiency with Microsoft 365 services and their security configurations
  • Hands-on experience with M365 including configuration, analysis and pivoting through large data sets and security best practices
  • Experience with Identity and Access Management and M365 services - OneDrive, Teams, SharePoint, Exchange Online, etc.
  • Proficient with Azure/M365 tenant capabilities and roles that support incident response/forensic analysis
  • Experience with various log aggregation/data analytics tools, such as Splunk, Elasticsearch, etc.
  • Industry-accredited certifications required
  • M365 security certifications preferred
  • Bachelor's degree/University degree or equivalent experience with 5+ years of relevant M365/Azure experience
  • Master's degree preferred

Nice to have:

  • M365 security certifications (ex: M365 Information Protection Administrator Associate, M365 Security Operations Analyst/Associate, M365 Certified Security Administrator Associate, etc.)
  • Other cloud security certifications (AWS, GCP, Azure, etc.)
  • Master's degree
What we offer:
  • Medical, dental & vision coverage
  • 401(k)
  • Life, accident, and disability insurance
  • Wellness programs
  • Paid time off packages including vacation, sick leave, and paid holidays
  • Discretionary and formulaic incentive and retention awards

Additional Information:

Job Posted:
September 06, 2025

Expiration:
December 31, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.