Senior Security Researcher

MicrosoftPublished 1 days agoFirst seen 16 hours ago
Overview

The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world.

Do you have a passion for helping Microsoft’s clients defend themselves against targeted exploitation? Are you interested in being intimately involved in the latest, cutting-edge developments in the security industry and having a direct impact on the security of all Microsoft customers? Do you want to be on the front lines of helping our customers go toe-to-toe against advanced adversaries? Are you interested in a fast-paced job full of new opportunities? Consider applying for the Senior Security Researcher position within the Applied Intelligence team.

As an Applied Intelligence Analyst, you will apply Microsoft Threat Intelligence Center (MSTIC)’s threat intelligence to live investigations across Microsoft's products, services, and customer estates. You sit where intelligence meets incident response: enriching investigations with threat actor context, driving attribution, producing actionable intelligence, discovering and building out emerging clusters of adversary activity, and feeding what you learn back into Microsoft's threat actor tracking mission. In this role, you will collaborate with internal teams (GHOST, DART, etc.) across incident response, threat intelligence, and product groups to protect both Microsoft and Microsoft’s customers. You will strengthen existing partnerships and build new ones with key organizations to deliver benefits to Microsoft and its customers.


Responsibilities
  • Investigation support. Providing threat intelligence support to proactive security research and reactive incident response engagements across both internal and customer-facing investigations.
  • Attribution and actor modeling. Ingesting, modeling, attributing, and documenting intelligence collected during engagements. Owning the attribution lane while investigation partners lead forensics and customer response.
  • Supporting Partner Teams: Providing attribution analysis and intelligence support to Microsoft Security partner teams investigating and responding to threats.
  • Product Improvements: Ensuring observations of threat actor exploitation of Microsoft products and services translate into product improvements.
  • Emerging threats. Discovering untracked clusters of activity with novel capabilities, developing them into tracked threat groups through in-depth research across the Diamond Model and multiple Microsoft telemetry sources, and helping Microsoft stay on top of the latest and newest threats.
  • Briefing and delivery. Delivering threat intelligence briefings to external customers and internal stakeholders. Supporting notifications to customers regarding imminent or ongoing attacker activity.
  • Feedback loop. Ensuring intelligence collected during reactive investigations— novel capabilities, infrastructure, targeting, or tradecraft — is promptly collated and surfaced back to Microsoft's actor tracking teams in MSTIC.
Qualifications

Required/minimum qualifications

Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.

  • Outstanding technical knowledge of adversary capabilities, infrastructure, and techniques, and the ability to develop new methods to discover and track them.
  • Experience tracking advanced financially motivated or state-sponsored adversaries using the Diamond Model; ability to characterize TTPs, infrastructure, and operational campaigns.
  • Demonstrated experience producing actionable intelligence that changed the outcome of an investigation or hardened a defended network.
  • Familiarity with host, log, and network forensics, common protocols, and a range of adversary command-and-control methods.
  • Demonstrated experience with log analysis and query languages (KQL/Kusto, SQL, or equivalent) across SIEM, identity, endpoint, or cloud telemetry.
  • Experience with large-scale cloud, identity, and endpoint telemetry.
  • Experience supporting incident response and familiarity with common IR procedures and tooling.
  • Ability to communicate findings clearly, with appropriate confidence language, to technical and executive audiences.

Preferred qualifications

Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.

Background in cloud and identity-based intrusions — token theft, OAuth abuse, SaaS-native tradecraft

Detection engineering or hunting query development at scale

Use of automation, data science, or AI tooling to accelerate triage, clustering, and analysis

Experience delivering customer or executive briefings under time pressure during active incidents

Working knowledge of malware used in targeted campaigns, including triage of malicious capabilities.

Familiarity with Microsoft security data sources - MDC, Defender XDR, Sentinel, Azure Resource Graph.

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.


Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.