Security Research Intern - AI Focus

Microsoft Microsoft · Big Tech · Herzliya, Tel Aviv District, IL · Security Research

AI Security Research Intern focused on developing autonomous systems to detect and disrupt cyber attacks in near real-time, leveraging LLMs and agentic frameworks.

What you'd actually do

  1. Investigate real-world advanced attacker TTPs and apply AI techniques (LLMs, agentic workflows) to support the development of high-fidelity, AI-augmented protection logic across complex cross-domain kill-chains.
  2. Apply security expertise combined with AI-driven methods to analyze massive telemetry sets using big-data query languages (KQL) and AI-driven analysis, reasoning over data to identify novel malicious patterns and engineer evidence-based detection rules.
  3. Contribute to the design and implementation of AI-powered capabilities that autonomously disrupt sophisticated threats in near real-time.
  4. Assist in the refinement of protection coverage by analyzing real-world attack telemetry to improve the accuracy and performance of existing detection logics.
  5. Contribute to a strategic feedback loop by documenting findings from attack data analysis to improve overall protection logic and system-wide security posture.

Skills

Required

  • Python
  • security research
  • threat hunting
  • detection engineering
  • AI technologies
  • LLMs
  • prompt engineering
  • agentic frameworks

Nice to have

  • C#
  • big-data query languages
  • KQL
  • SQL
  • LLM
  • prompt engineering
  • agentic AI frameworks
  • LangChain
  • Semantic Kernel
  • AutoGen
  • adversarial behavior

What the JD emphasized

  • Must have at least 3 additional semesters before graduation – graduation date Summer 27 or later.
  • Available to work 3 days a week.
  • Proven hands-on experience in security research, threat hunting, or detection engineering roles
  • Hands-on experience with AI technologies, whether through building ML models, working with LLMs and prompt engineering, experimenting with agentic frameworks, or applying AI to academic or personal projects
  • Experience with LLMs, prompt engineering, or agentic AI frameworks (e.g., LangChain, Semantic Kernel, AutoGen) — academic projects or personal exploration count.

Other signals

  • AI-powered research transformed into autonomous defense systems
  • AI Security Research Intern
  • agentic pipelines and LLM-based threat analysis