CareerPlanSign in

Principal Security Research - Microsoft Defender ( Identity Threat Detection and Response)

Israel, Multiple Locations, Multiple Locations💼 Full-time🗓 2026-09-23 → 2026-09-25

Core

Define technical direction and strategy for identity threat detection, leading end-to-end research initiatives to surface novel threats and design robust detection logics across the kill-chain.

Role type

Principal Security Researcher (Identity Threat Detection)

Builds

Shipped detection capabilities and measurable customer protection impact for identity protection products.

Domain

Enterprise Security / Identity Threat Detection and Response (ITDR)

Deliverable

production ML models | product features

Required skills

Identity-based threat analysis, modern attacker kill chain, MITRE ATT&CK, identity protocols (Kerberos, NTLM, LDAP, OAuth 2.0, OpenID Connect, SAML), cloud identity architectures (Entra ID), OS internals and forensics, lateral movement techniques, credential theft analysis, cloud forensics, Generative AI tooling and workflow design, technical leadership, cross-org influence, mentoring.

Preferred skills

Experience in elite technology units (e.g., IDF), established external thought leadership (papers, talks, CVEs, open-source).

Technologies

C++, C#, Java, Python, Entra ID, KQL.

Responsibilities

Set multi-quarter strategy from threat landscape framing to shipped detection, lead deep investigation of data across identity sources, design sophisticated detection logics, partner with product and engineering teams to shape strategy, mentor and grow other researchers, define patterns and build AI-assisted workflows for research throughput.

Seniority

Principal (IC5), strategy & mentorship

Sourced via microsoft · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.