This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are Cloud Threat protection Research team within Microsoft Threat Protection, working at the heart of how Microsoft protects cloud and AI workloads at global scale. Our research directly informs and powers protections in Microsoft Defender, where we study real attacker behaviour, analyse production incidents, and design defences that protect some of the world’s largest enterprises, governments, and critical infrastructure. The problems we work on are current, complex, and high‑impact—rooted in how modern cloud platforms are actually attacked and defended.
Job Responsibility:
Research real‑world hybrid threats across cloud services, end point, identity and AI systems
Analyze live attacker behavior and production incidents to build high‑signal detections
Design multi‑cloud and enterprise protections that ship in Microsoft Defender
Collaborate closely with product, engineering, and global research teams to turn ideas into impact
Partner with strong in‑house AI teams to advance AI security, detection quality, and explainability
Build innovative tools, automation, and research prototypes at global scale
Operate in a high‑trust, ownership‑driven team culture that values technical depth and innovation
Requirements:
5+ years of experience in cybersecurity, with strong hands-on understanding of the modern attacker kill chain, MITRE ATT&CK framework, and evolving cloud-based threats, including attacks targeting Enterprise Apps, and emerging AI-driven applications
Proven experience securing cloud and containerized environments, with hands‑on knowledge of Azure, AWS, and/or GCP, and technologies such as Kubernetes, container platforms, Storage, Key Vault, DNS and cloud services
Deep knowledge of adversary tooling, red team frameworks, and attacker techniques, with the ability to analyze, simulate, and interpret real-world attacker behaviors across cloud ecosystems
Proficiency in at least one programming language (e.g., Python, C, or C++) for building research prototypes, internal tools, automation, or detection logic
Strong proficiency in query languages such as KQL, SQL, or Cypher for large-scale telemetry analysis, threat hunting, behavioral investigations, and detection validation
Experience working with large-scale datasets to support detection development, proactive threat hunting, behavioral analytics, and signal quality improvement
Strong collaboration and communication skills, with the ability to clearly articulate research insights, influence product and engineering decisions, and work effectively with partner teams, including Engineering, Data Science, and incident response stakeholders
Bachelor’s or Master’s degree in Computer Science, Engineering, or a related technical discipline, or equivalent practical experience in security research or threat detection