CareerPlanGet AI match score →

Principal Security Research Manager, Applied Threat Intel & Threat Response - Microsoft Security

United States, Washington, Redmond💼 Full-time🗓 2026-07-23 → 2026-07-29

Recruit, develop, and retain a high-performing blended team spanning two distinct but complementary disciplines: finished intelligence production and threat response operations. Set clear goals for each function, connect individual work to team and business objectives, and adapt priorities as the threat landscape and organizational needs evolve. Mentor analysts and responders on tradecraft, career development, and the standards that define great intelligence and response work. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. ○ OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. ○ OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. These requirements include, but are not limited to the following specialized security screenings: This position requires verification of U.S. citizenship due to citizenship‑based legal restrictions. Specifically, this position supports United States federal, state, and/or local government agency customers and is subject to certain citizenship‑based restrictions where required or permitted by applicable law. To meet this legal requirement, and as a condition of employment, the successful candidate's citizenship will be verified via a valid passport. Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 5+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. ○ OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. ○ OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 12+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection. 3+ years people management and/or informal/indirect team leadership experience. Demonstrated experience producing or overseeing finished threat intelligence reporting for technical and/or executive audiences. 10+ years of experience in cyber threat intelligence, threat hunting, incident response, or a closely related security discipline. Demonstrated track record leading a finished intelligence production function — owning report quality, publication standards, and the analytic tradecraft that makes intelligence credible and actionable. Experience managing or operating across both intelligence production and incident response disciplines, with fluency in the tension between long-horizon analysis and rapid-response demand. Portfolio of public or customer-facing intelligence writing (actor profiles, campaign reports, vulnerability analyses, or equivalent). Understanding of adversary tradecraft and frameworks including MITRE ATT&CK, the Diamond Model, Cyber Kill Chain, and structured analytic techniques. Experience with endpoint, cloud, network, and identity-based attacks and datasets. Programming or scripting background (Python, KQL, PowerShell, or equivalent) sufficient to evaluate and guide technical work on the team. Familiarity with AI-assisted intelligence workflows and automation approaches for threat triage, enrichment, and intelligence delivery at scale. MSSecurity Security Research M5 - The typical base pay range for this role across the U.S. is USD $142,800 - $274,800 per year. There is a different range applicable to specific work locations, within the San Francisco Bay area and New York City metropolitan area, and the base pay range for this role in those locations is USD $188,000 - $304,200 per year. Certain roles may be eligible for benefits and other compensation. Establish and maintain analytic standards, tradecraft guidance, and peer review practices that ensure your team's finished intelligence is credible, prescriptive, and audience-appropriate from SOC analyst to C-suite. Ensure threat response practitioners are trained, calibrated, and ready for on-call rotation and rapid-response engagements. Develop trusted relationships across the intelligence community, including industry partners, external organizations, and agencies engaged in tracking criminal threat actors. Build and operationalize a hybrid human + agentic intelligence team, applying AI technologies, automation, and workflow innovation to improve scale, speed, and insight generation.

Sourced via microsoft · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply at Microsoft ↗