Overview
Set the technical direction for a major area of our identity protection research charter, owning the multi-quarter strategy from threat landscape framing to shipped detection and measurable customer protection impact. Drive multiple concurrent end-to-end research initiatives, breaking ambiguous problems into tractable workstreams and unblocking the team on the hardest technical questions. Lead deep investigation and research of data across identity and adjacent sources to surface novel threats, attacker tradecraft, and detection opportunities others miss. Stay ahead of the evolving attacker landscape and design robust, sophisticated detection logics across the entire kill-chain — raising the bar on quality, coverage, and resilience to attacker evasion. Influence across organizational boundaries — partner with product management, engineering, data science, and peer research teams to shape
Full job description
Full Job Description
Set the technical direction for a major area of our identity protection research charter, owning the multi-quarter strategy from threat landscape framing to shipped detection and measurable customer protection impact. Drive multiple concurrent end-to-end research initiatives, breaking ambiguous problems into tractable workstreams and unblocking the team on the hardest technical questions. Lead deep investigation and research of data across identity and adjacent sources to surface novel threats, attacker tradecraft, and detection opportunities others miss. Stay ahead of the evolving attacker landscape and design robust, sophisticated detection logics across the entire kill-chain — raising the bar on quality, coverage, and resilience to attacker evasion. Influence across organizational boundaries — partner with product management, engineering, data science, and peer research teams to shape product strategy, define new identity protection capabilities, and align roadmaps on a data-driven foundation. Mentor and grow other researchers (IC3-IC4), elevating the technical bar of the team through code/design review, research coaching, and apprenticeship on complex investigations. Shape how the team and discipline leverage Generative AI — define patterns, evaluate tools, and build durable AI-assisted workflows that scale research throughput across data triage, hypothesis generation, code and KQL authoring, and detection synthesis. You have at least 10 years of experience in security research. Proficiency in developing with either C++, C#, Java or Python. You have experience leading a feature from design through to production delivery (design, coding, testing, deployment). 8+ years of experience in cybersecurity research, with a strong background in the modern attacker kill chain and MITRE ATT&CK, and deep expertise in identity-based threats and identity protection, ideally in the context of enterprise security or Identity Threat Detection and Response (ITDR). B.Sc. or M.Sc. in Computer Science, Software Engineering, or equivalent practical experience (e.g., service in an elite technology unit in the IDF). Demonstrated track record of leading multi-quarter research initiatives end-to-end from problem framing through execution to shipped outcomes and measurable customer impact, across organizational boundaries. Demonstrated technical leadership and influence beyond your immediate team, including cross-org partnerships, setting technical standards, mentoring senior peers, driving consensus on ambiguous technical decisions, and influencing without authority. Deep technical expertise in OS internals and forensics, including key forensic artifacts related to lateral movement and credential theft, as well as strong knowledge of identity protocols (e.g., Kerberos, NTLM, LDAP, OAuth 2.0, OpenID Connect, SAML) and modern cloud identity architectures such as Entra ID. Experience with cloud forensics and hybrid environments, including identity attack artifacts and lateral movement techniques across on-premises and cloud environments. Demonstrated fluency with Generative AI tools and AI-assisted workflows, including prompt design, model output validation, and building reusable AI-assisted patterns for security research, detection engineering, or threat intelligence at scale. Established external thought leadership in the security research community, demonstrated through research papers, conference talks, high-impact blogs, CVEs, or open-source contributions. Prior experience operating at Principal (IC5) or equivalent level, with a drive to tackle the hardest and most ambiguous problems in the identity threat landscape.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Microsoft Opportunities →