CareerPlanGet AI match score →

Senior Security Researcher

United States, Washington, Redmond💼 Full-time🗓 2026-07-21 → 2026-07-31

Core

Conducting vulnerability research, threat analysis, and anomaly detection to identify and mitigate security risks within large-scale computing environments.

Role type

Senior Security Researcher (DFIR/Threat Intelligence)

Builds

Production security models, forensic artifacts, and threat intelligence reports

Domain

Cybersecurity, Digital Forensics, Threat Intelligence

Deliverable

production ML models | research | client delivery

Required skills

Vulnerability research, threat analysis, anomaly detection, forensic log analysis, Windows internals, Linux/macOS forensic analysis, TTPs identification, EDR/SIEM proficiency

Preferred skills

Active Directory expertise, third-party cybersecurity solution knowledge, digital forensics certifications (CISSP, SANS GIAC)

Technologies

SIEM, EDR, HIDS, NIDS, Active Directory, Windows, Linux, macOS

Responsibilities

Analyze sophisticated threat actor evidence including IOCs, IOAs, and TTPs; investigate forensic log artifacts in SIEM, web server, AV, and protection logs; perform forensic analysis and threat hunting on Linux and macOS systems; research vulnerabilities and model threat scenarios.

Seniority

Senior, hands-on IC

Rewrite
## About the role Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience. ## Requirements - Active Directory subject matter expertise - Experience with sophisticated threat actor evidence including familiarity with typical Indicators of Compromise (IOCs), Indicators of Activity (IOAs) and Tools, Techniques and Procedures (TTPs) - Experience with various forensic log artifacts found in SIEM logs, web server logs, AV logs, protection logs such as HIDS and NIDS logs - Excellent understanding of Windows internals and where trace evidence can be found - Knowledge of third-party cybersecurity solutions, especially EDR and SIEM solutions - Linux and/or macOS forensic analysis and threat hunting skills - Technical certifications based on domain (e.g., Azure, SharePoint) - Investigation/Cybersecurity/Digital Forensics/DFIR certifications (e.g. CISSP, SANS GIAC, etc) ## Citizenship & Citizenship Verification This role will require access to information that is controlled for export under export control regulations, potentially under the U.S. International Traffic in Arms Regulations or Export Administration Regulations, the EU Dual Use Regulation, and/or other export control regulations. As a condition of employment, the successful candidate will be required to provide either proof of their country of citizenship or proof of their U.S. permanent residency or other protected status (e.g., under 8 U.S.C. 1324b(a)(3)) for assessment of eligibility to access the export controlled information. To meet this legal requirement, and as a condition of employment, the successful candidate's citizenship will be verified with a valid passport. Lawful permanent residents, refugees, and asylees may verify status using other documents, where applicable.
Sourced via microsoft · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply at Microsoft ↗