Principal Security Research - Microsoft Defender ( Identity Threat Detection and Response)
Core
Define technical direction and strategy for identity threat detection, leading end-to-end research initiatives to surface novel threats and design robust detection logics across the kill-chain.
Role type
Principal Security Researcher (Identity Threat Detection)
Builds
Shipped detection capabilities and measurable customer protection impact for identity protection products.
Domain
Enterprise Security / Identity Threat Detection and Response (ITDR)
Deliverable
production ML models | product features
Required skills
Identity-based threat analysis, modern attacker kill chain, MITRE ATT&CK, identity protocols (Kerberos, NTLM, LDAP, OAuth 2.0, OpenID Connect, SAML), cloud identity architectures (Entra ID), OS internals and forensics, lateral movement techniques, credential theft analysis, cloud forensics, Generative AI tooling and workflow design, technical leadership, cross-org influence, mentoring.
Preferred skills
Experience in elite technology units (e.g., IDF), established external thought leadership (papers, talks, CVEs, open-source).
Technologies
C++, C#, Java, Python, Entra ID, KQL.
Responsibilities
Set multi-quarter strategy from threat landscape framing to shipped detection, lead deep investigation of data across identity sources, design sophisticated detection logics, partner with product and engineering teams to shape strategy, mentor and grow other researchers, define patterns and build AI-assisted workflows for research throughput.
Seniority
Principal (IC5), strategy & mentorship