This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Microsoft Threat Protection Research is recruiting security professionals with experience and passion to apply AI techniques to protect customers. We are looking for a candidate to join the Microsoft Defender Experts research team to help us deliver Managed Security Services to our customers.
Job Responsibility:
Leverage AI techniques and security operations experience to explore and correlate large data sets to uncover novel attack techniques and hunting in enterprise customer environments.
Partner with researchers and engineering teams, and Defender Experts analysts, to use AI to improve our service delivery outcomes.
Use advanced techniques and in-the-wild data to identify, prioritize, and target complex security issues that cause negative impact to customers.
Design and lead experiments in the use of AI to transform our managed services business.
Requirements:
4+ years experience in cybersecurity, software development lifecycle, large-scale computing, modeling, and/or anomaly detection
4+ years of professional experience in investigating or researching cyber threats, understanding attacker methodology, tools, and infrastructure
Excellent communication skills and investigative practices.
Experience in security research, incident response and attacker tradecraft.
Experience applying generative AI to the information security domain.
Experience creating solutions with a variety of large language models, understanding differences between models and how to compare them.
Experience with hosted AI tools such as Azure Foundry, Azure OpenAI Service.
Experience working with extremely large data sets, using tools and scripting languages like Excel, KQL, SQL, Python, Splunk, and Power BI.
Experience working with detection methodologies across multiple platforms.
Ability to utilize attacker uptake and impact to prioritize security detection and remediation tasks.
Experience with endpoint, cloud, network, and identity-based attacks and datasets.
Comprehensive OS security/internals knowledge.
Understanding of network protocols and analytical experience with network infrastructure data & telemetry.
Reverse-engineering with static and behavioral binary analysis experience.
Functional understanding of common threat analysis models such as the Diamond Model, Cyber Kill Chain, and MITRE ATT&CK.
Nice to have:
Programming or scripting background (Python, PowerShell, C, C++, etc.) is a plus.