This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Microsoft Security aspires to make the world a safer place for all. We empower every user, customer, and developer with a security cloud that protects them with end-to-end, simplified solutions across heterogeneous environments — and across our own internal estate. Our culture is centered on a growth mindset, inspiring excellence, and bringing our best each day to create innovations that impact billions of lives. Come build one of Microsoft's most exciting security products: Identity Threat Detection and Response (ITDR). As cyber-attacks grow more sophisticated, we help enterprises detect, investigate, and autonomously protect against advanced identity-based attacks and data breaches — from nation-state actors to large-scale ransomware operators. Our research team combines deep knowledge of the attacker landscape and tradecraft to deliver the innovations needed to uncover and stop even the most well-funded adversaries. We are seeking an experienced Senior Security Researcher, excited by finding new attacks, to join our research team and focus on detecting and autonomously protecting against sophisticated enterprise attacks. The role spans novel attack-technique research, big-data analysis over rich sensor data, identifying the optics needed to expose malicious behavior, and crafting detection and protection logic so compromise does not go undetected. We expect our researchers to fluently leverage Generative AI to accelerate every stage of their work — from hypothesis generation and code prototyping to large-scale data triage and detection authoring.
Job Responsibility
Own end-to-end large research projects that deliver identity protection against the most prevalent threats in the landscape
conduct in-depth investigation and research of data across multiple identity and additional sources to identify threats and sophisticated attack incidents
keep up to date with the latest trends in cyber-attacks and create robust, sophisticated detection logics across the entire kill-chain
collaborate with product management, security, and engineering teams across the company to design innovative solutions and new identity protection capabilities and validate their effectiveness using a data-driven approach
collaborate with data science teams to understand, identify, and implement detection gaps, capabilities, assumptions, and improvements
leverage Generative AI tooling to scale research throughput
demonstrate thought leadership and engage and enlighten others through compelling, meaningful content and informative sessions
Requirements
6+ years of cyber security experience
2+ years working hands-on with identity-based attacks
Windows internals knowledge
working knowledge of main identity protocols (e.g., Kerberos, NTLM, LDAP, OAuth 2.0, SAML)
fluency leveraging Generative AI tools
Nice to have
B.Sc./M.Sc. in Computer Science or related technical discipline
good knowledge of at least one programming language such as C# (preferred), Python, or C++, and at least one query language such as KQL, SQL, or Cypher
experience with Windows and/or Cloud forensics
experience authoring security research (papers, blogs, conference talks such as BlueHat / Black Hat / DEF CON, or CVEs)
experience building or applying AI/LLM-assisted workflows for security research, detection engineering, or threat intelligence at scale
excellent cross-group, leadership, and interpersonal skills