Overview
Investigate real world advanced attacker TTPs to develop high-fidelity protection signals, and robust logic across complex kill-chains. Design and implement innovative capabilities that autonomously prevent, detect and disrupt sophisticated threats in near real-time. Infuse deep security expertise into the analysis of massive telemetry sets using big-data query languages, reasoning over data to identify novel malicious patterns, and drive evidence-based research decisions. Partner with engineering and product teams to share research insights, validate protection concepts, and push ideas forward into production-ready protection at a global scale. Contribute expert insights to a strategic feedback loop by analyzing real-world attack data and telemetry to refine protection coverage and accuracy. 4+ years of hands-on experience in security research or threat hunting, with a specialized focus
Full job description
Full Job Description
Investigate real world advanced attacker TTPs to develop high-fidelity protection signals, and robust logic across complex kill-chains. Design and implement innovative capabilities that autonomously prevent, detect and disrupt sophisticated threats in near real-time. Infuse deep security expertise into the analysis of massive telemetry sets using big-data query languages, reasoning over data to identify novel malicious patterns, and drive evidence-based research decisions. Partner with engineering and product teams to share research insights, validate protection concepts, and push ideas forward into production-ready protection at a global scale. Contribute expert insights to a strategic feedback loop by analyzing real-world attack data and telemetry to refine protection coverage and accuracy. 4+ years of hands-on experience in security research or threat hunting, with a specialized focus on identity, cloud, or AI-based threat scenarios. Deep understanding of the threat landscape, including modern attacker techniques and complex kill-chains, with a focus on platform internals across OS, Cloud Workloads and Identity platforms. Experience hunting across diverse signal sources, effectively uncovering threats within on-premises, hybrid, and cloud environments. Programming proficiency (e.g., Python, C#, or similar), with a proven ability to develop and ship production-ready protection logic.Demonstrated ability to work effectively in cross-functional teams, bridging the gap between deep research and scalable engineering. Preferred Qualifications B.Sc. or M.Sc. in Computer Science or Software Engineering OR/AND related field Public track record of security research, such as technical blog posts, whitepapers, or presentations at major industry conferences. Experience in offensive security or adversary simulation.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Microsoft Careers →