Principal Security Research Manager, Applied Threat Intel & Threat Response - Microsoft Security
Core
Lead a blended team of intelligence analysts and threat responders to produce finished threat intelligence and execute rapid-response operations for US government agencies.
Role type
Principal Security Research Manager (Applied Threat Intel & Threat Response)
Builds
Finished intelligence reports, threat response playbooks, and hybrid human+AI intelligence workflows
Domain
Cybersecurity, Threat Intelligence, Incident Response, US Federal/State/Local Government
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Threat intelligence production, incident response leadership, adversary tradecraft analysis, structured analytic techniques, team mentorship, AI-assisted intelligence workflows, programming/scripting (Python, KQL, PowerShell), endpoint/cloud/network/identity attack analysis
Preferred skills
Experience managing both intelligence production and incident response functions, fluency in MITRE ATT&CK/Diamond Model/Cyber Kill Chain, building hybrid human+agentic teams
Technologies
Python, KQL, PowerShell, MITRE ATT&CK, Diamond Model, Cyber Kill Chain
Responsibilities
Recruit and develop high-performing teams across intelligence and response disciplines, set goals connecting individual work to business objectives, mentor analysts on tradecraft and career development, establish analytic standards and peer review practices, ensure threat response practitioners are trained for rapid-response engagements, build relationships with the intelligence community and external partners, operationalize hybrid human+AI intelligence workflows
Seniority
Principal, strategy & mentorship
