Overview
Lead attribution and threat actor analysis by collecting, modeling, attributing, and documenting intelligence gathered during investigations. Serve as the primary owner for attribution efforts while partnering with incident response teams responsible for forensics and customer engagement. Communicate intelligence to diverse audiences through written reports, executive briefings, and customer-facing presentations. Support customer notifications related to imminent, ongoing, or impactful threat activity. Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection, OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years ex
Full job description
Full Job Description
Lead attribution and threat actor analysis by collecting, modeling, attributing, and documenting intelligence gathered during investigations. Serve as the primary owner for attribution efforts while partnering with incident response teams responsible for forensics and customer engagement. Communicate intelligence to diverse audiences through written reports, executive briefings, and customer-facing presentations. Support customer notifications related to imminent, ongoing, or impactful threat activity. Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection, OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR equivalent experience. government security screening requirements as required for this role. are not limited to the following specialized security screenings: The successful candidate must have an active U.S. Government Secret Security Clearance. You will be asked to provide clearance verification information prior to an offer of employment. background check upon hire/transfer and every two years thereafter. Citizenship & Citizenship Verification: This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. Specifically, this position supports United States federal, state, and/or local United States government agency customer and is subject to certain citizenship-based restrictions where required or permitted by applicable law. To meet this legal requirement, citizenship will be verified via a valid passport, or other approved documents, or verified US government Clearance Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience Background in cloud and identity-based intrusions — token theft, OAuth abuse, SaaS-native tradecraft Detection engineering or hunting query development at scale Use of automation, data science, or AI tooling to accelerate triage, clustering, and analysis Experience delivering customer or executive briefings under time pressure during active incidents Working knowledge of malware used in targeted campaigns, including triage of malicious capabilities. Strong technical knowledge of adversary capabilities, infrastructure, and techniques, and the ability to develop new methods to discover and track them. Experience tracking advanced financially motivated or state-sponsored adversaries using the Diamond Model; ability to characterize TTPs, infrastructure, and operational campaigns. Demonstrated experience producing actionable intelligence that changed the outcome of an investigation or hardened a defended network. Familiarity with host, log, and network forensics, common protocols, and a range of adversary command-and-control methods. Demonstrated experience with log analysis and query languages (KQL/Kusto, SQL, or equivalent) across SIEM, identity, endpoint, or cloud telemetry. Experience with large-scale cloud, identity, and endpoint telemetry. Experience supporting incident response and familiarity with common IR procedures and tooling. Ability to communicate findings clearly, with appropriate confidence language, to technical and executive audiences.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
Verified from public schema.org JobPosting structured data on the official source page. The complete published description, responsibilities, requirements and benefits were normalized when present; unstated facts were not inferred.
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Microsoft Opportunities →