Senior Security Engineer

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Security Research

Senior Security Engineer focused on identity security, translating threats into AI-first engineering requirements, analyzing advanced attacks using large-scale telemetry, designing detections, and building automation for investigation and response within Microsoft Security's Identity Security Breach Response Squad.

What you'd actually do

  1. Translate emerging security threats into clear, actionable engineering requirements, partnering with product and engineering teams to drive AI‑first solutions that close gaps quickly and scale protections across identity systems.
  2. Investigate and analyze advanced identity based attacks, including token theft, certificate abuse, federation compromise, workload identity misuse, MFA bypass, and hybrid/cloud attack paths.
  3. Perform deep security investigations using large scale telemetry across cloud identity systems, correlating signals to distinguish malicious activity from expected service behavior.
  4. Design high fidelity detections based on adversary invariants and abuse patterns.
  5. Build or contribute to automation and tooling that accelerates investigation, detection, and remediation at cloud scale.

Skills

Required

  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
  • Experience in security research, threat analysis, incident response, or detection engineering.
  • Understanding of identity and access technologies, such as authentication and authorization protocols (OAuth, OIDC, SAML), tokens, certificates/PKI, and MFA.
  • Experience analyzing security telemetry at scale (for example, using Kusto, SQL, or similar analytics platforms).
  • Ability to translate complex technical findings into clear guidance for engineers and security stakeholders.

Nice to have

  • Kusto
  • SQL

What the JD emphasized

  • AI-first solutions
  • large scale telemetry
  • advanced identity based attacks

Other signals

  • AI-first solutions
  • advanced identity based attacks
  • large scale telemetry
  • automation and tooling