This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world. The Microsoft Threat Intelligence Center (MSTIC) is recruiting experienced nation-state threat hunters – with highly honed threat intelligence analysis skills. MSTIC provides unique insight on threats to protect Microsoft and our customers and is responsible for delivering timely threat intelligence across our product and services teams. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As a Threat Intelligence Analyst in MSTIC, you will track and analyze sophisticated threat actors (including nation-state and advanced persistent threats) and translate intelligence into actionable outcomes that improve Microsoft security products, services, and defenses. You will combine deep technical expertise with analytic tradecraft to drive end-to-end investigations, detect adversary activity, and support detection, hunting, and disruption efforts across Microsoft’s ecosystem. The role includes close collaboration with internal teams and external partners, contributing to real-time response, customer engagements, and broader understanding of adversary ecosystems and campaigns.
Job Responsibility
As a threat intelligence analyst, you will be responsible for tracking sophisticated adversaries and use your technical knowledge of adversary capabilities, infrastructure, and techniques
You will define, develop, and implement techniques to discover and track current adversaries and identify the attacks of tomorrow
You will produce actionable intelligence, proactively drive hunting and detection capabilities, and contribute to the disruption of adversary activity to protect Microsoft and its customers
In this role, you will collaborate closely with MSTIC and partner with security, engineering, and product teams across Microsoft to protect Microsoft assets, products, and customer environments
You will strengthen existing partnerships and build new ones with key organizations to enhance collective defense and improve product and service security
Requirements
You have at least 6 years of experience producing actionable threat intelligence on targeted and advanced persistent threats, with demonstrable impact on network and host defenses
Proven expertise tracking and investigating APT adversaries, across all stages of the attack chain
Strong ability to analyze and hunt adversary behaviour end-to-end, map attack chains, and communicate clear, evidence-based intelligence to technical and executive audiences
Ability to quickly adapt to a rapidly evolving telemetry landscape
Nice to have
Experience operationalizing threat intelligence and hunting methodologies at scale, leveraging AI and automation, Python, or scalable analytical workflows
Analysis of sophisticated malware and targeted attacks against enterprise or government environments, including identification of large-scale and supply chain attack patterns
Cloud intrusion analysis in adversary operations
Host forensic investigation and log analysis of advanced targeted adversaries
Proven track record in producing actionable Threat Intelligence on APTs based on telemetry analysis