Security Researcher II /Senior Security Researcher - Microsoft Defender (Multiple Roles)
Core
Investigate advanced attacker TTPs to develop high-fidelity protection signals and robust logic across complex kill-chains; design and implement capabilities that autonomously prevent, detect, and disrupt sophisticated threats in near real-time.
Role type
Senior IC security researcher (threat intelligence & protection engineering)
Builds
Production-ready protection logic and autonomous detection/prevention capabilities for Microsoft Defender
Domain
Cybersecurity, Threat Intelligence, Cloud Security, Identity Security
Deliverable
production ML models | product features
Required skills
Advanced threat hunting, TTP analysis, kill-chain mapping, big-data query languages, data reasoning, Python, C#, cross-functional collaboration, platform internals knowledge (OS, Cloud, Identity)
Preferred skills
Offensive security, adversary simulation, public security research track record (blogs, whitepapers, conference presentations)
Technologies
Python, C#, Big-data query languages
Responsibilities
Analyze real-world attack data and telemetry to identify novel malicious patterns; Partner with engineering teams to validate protection concepts and push ideas to production; Refine protection coverage and accuracy through strategic feedback loops; Develop innovative capabilities to autonomously prevent and disrupt threats.