Senior Security Researcher
Core
Apply Microsoft Threat Intelligence Center (MSTIC) threat intelligence to live investigations across Microsoft's products, services, and customer estates to defend against targeted exploitation.
Role type
Senior Security Researcher (Applied Intelligence Analyst)
Builds
Actionable threat intelligence, attribution models, and product security improvements for Microsoft and its customers.
Domain
Cybersecurity, Threat Intelligence, Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery
Required skills
Threat actor modeling and attribution, Log analysis and query languages (KQL/Kusto, SQL), Large-scale cloud/identity/endpoint telemetry analysis, Incident response procedures, Diamond Model framework, Malware triage
Preferred skills
Cloud and identity-based intrusion detection (token theft, OAuth abuse), Detection engineering and hunting query development, Automation and data science tooling for triage, Executive briefing under pressure
Technologies
MSTIC, KQL/Kusto, SQL, SIEM, Azure Resource Graph, Defender XDR, Sentinel
Responsibilities
Provide threat intelligence support for proactive research and reactive incident response; Ingest, model, and attribute intelligence to drive adversary tracking; Support partner teams with attribution analysis; Translate threat observations into product improvements; Discover and track emerging untracked threat clusters; Deliver threat intelligence briefings to customers and stakeholders; Feed novel capabilities and tradecraft back to MSTIC.
Seniority
Senior, hands-on IC