This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Join one of the elite research teams powering Microsoft Defender, the dominant market leader in XDR, SIEM, Cloud, and AI Security. We protect the world’s largest enterprises by analyzing trillions of signals to protect against sophisticated cyberattacks across hybrid and multi-cloud environments. We are currently hiring for multiple Security Research positions across our Microsoft Defender Research teams in Israel. By applying to this unified pipeline, you will be considered for a high-impact role (at either the Security Researcher II or Senior Security Researcher role) within one of our specialized groups, including Autonomous Attack Disruption, Cloud Workload Protection, Identity Research, Posture Research, or Security for AI.
Job Responsibility:
Investigate real world advanced attacker TTPs to develop high-fidelity protection signals, and robust logic across complex kill-chains
Design and implement innovative capabilities that autonomously prevent, detect and disrupt sophisticated threats in near real-time
Infuse deep security expertise into the analysis of massive telemetry sets using big-data query languages, reasoning over data to identify novel malicious patterns, and drive evidence-based research decisions
Partner with engineering and product teams to share research insights, validate protection concepts, and push ideas forward into production-ready protection at a global scale
Contribute expert insights to a strategic feedback loop by analyzing real-world attack data and telemetry to refine protection coverage and accuracy
Requirements:
At least 4+ years of hands-on experience in security research or threat hunting, with a specialized focus on identity, cloud, or AI-based threat scenarios
Deep understanding of the threat landscape, including modern attacker techniques, AI-driven threats, and complex kill-chains, with a focus on platform internals across OS, Cloud Workloads and Identity platforms
Proven ability to reason over large-scale datasets using big-data query languages, applying security expertise to identify novel patterns and make evidence-based decisions
Familiarity with cloud environments (e.g., Azure, AWS) and the specific security challenges inherent to hybrid and multi-cloud infrastructures in large enterprise customers
Experience hunting across diverse signal sources, effectively uncovering threats within on-premises, hybrid, and cloud environments
Nice to have:
B.Sc. or M.Sc. in Computer Science, Software Engineering, or a related field, or equivalent practical experience (e.g., relevant industry or military experience)
Programming proficiency (e.g., Python, C#, or similar), with a proven ability to develop and ship production-ready protection logic
Public track record of security research, such as technical blog posts, whitepapers, or presentations at major industry conferences
Experience in offensive security or adversary simulation
Demonstrated ability to work effectively in cross-functional teams, bridging the gap between deep research and scalable engineering