This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to end, simplified solutions. The Microsoft Security organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate.
Job Responsibility:
Identifying potential threats, allowing for proactive defense before an actual incident
Building proof-of-concept, prototype, and production-ready threat hunting tools, automations, and new capabilities
Driving product and tooling improvements by conveying learnings from threat hunting and incident response at scale to engineering partner teams
Monitor, maintain, and iterate on proprietary solutions that enable our team to threat hunt
Implement security controls of relevant mitigations to defend against current and future threat landscape
Contribute across teams in producing extensible, testable, and maintainable code
Strong problem-solving skills, a passion for quality, and the ability to manage ambiguity, short timelines, and changing priorities
Requirements:
5+ years experience in software or systems development lifecycle and cybersecurity OR bachelor’s degree in computer science or related field
Professional experience with developing automation with at least one of the following: PowerShell, Python, Bash
Professional experience with Azure technology including but not limited to
EntraId, Azure Front Door, Networking, ARM Deployment, Logic Apps, Functions, Automation, Storage, Alerting
Microsoft Cloud Background Check
Nice to have:
7+ years experience in software development lifecycle and cybersecurity OR master’s in computer science or related field
Proven knowledge of security fundamentals across Microsoft platforms (Client, Server, Cloud)
Familiarity and understanding of SQL or Kusto Query Language (KQL) queries (or experience with large database/SIEM query languages such as Splunk/Humio/Kibana, etc.)
Familiarity and understanding of Jupyter Notebooks, or building equivalent threat hunting automations with scripting languages
Experience with sophisticated threat actor evidence including familiarity with typical Indicators of Compromise (IOCs), Indicators of Activity (IOAs) and Tools, Techniques and Procedures (TTPs)
Microsoft Azure platform knowledge and experience
Familiar with various forensic log artifacts
Familiarity with Microsoft security products stack
Familiar with Windows, Linux, and/or macOS forensic analysis