Senior Security Researcher

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Security Research

Senior Security Researcher focused on detecting and autonomously protecting against sophisticated enterprise identity-based attacks. The role involves novel attack-technique research, big-data analysis, identifying detection optics, and crafting detection/protection logic. It requires leveraging Generative AI tools to accelerate research stages like hypothesis generation, code prototyping, data triage, and detection authoring. The goal is to deliver identity protection against prevalent threats, from hypothesis to shipped detection and customer impact.

What you'd actually do

  1. Own end-to-end large research projects that deliver identity protection against the most prevalent threats in the landscape, from initial threat hypothesis to shipped detection and customer protection impact.
  2. Conduct in-depth investigation and research of data across multiple identity and additional sources to identify threats and sophisticated attack incidents.
  3. Keep up to date with the latest trends in cyber-attacks and create robust, sophisticated detection logics across the entire kill-chain.
  4. Collaborate with product management, security, and engineering teams across the company to design innovative solutions and new identity protection capabilities and validate their effectiveness using a data-driven approach.
  5. Collaborate with data science teams to understand, identify, and implement detection gaps, capabilities, assumptions, and improvements.

Skills

Required

  • 6+ years of experience in cyber security
  • modern attacker kill-chain and MITRE ATT&CK
  • identity-based threat scenarios
  • Windows internals knowledge
  • Kerberos, NTLM, LDAP, OAuth 2.0, SAML
  • C#, Python, or C++
  • KQL, SQL, or Cypher
  • Generative AI tools (e.g., GitHub Copilot, Security Copilot, ChatGPT/Claude, or equivalent LLM-based workflows)
  • prompt design
  • validating model output
  • integrating AI assistance into investigation, coding, and detection authoring

Nice to have

  • Experience in authoring security research papers, blogs, or books
  • Windows forensics
  • Cloud forensics
  • building or applying AI/LLM-assisted workflows to security research, detection engineering, or threat intelligence at scale

What the JD emphasized

  • identity protection
  • sophisticated enterprise attacks
  • Generative AI tooling
  • detection

Other signals

  • Leverage Generative AI tooling to scale research throughput
  • building or applying AI/LLM-assisted workflows to security research
  • detect, investigate, and autonomously protect against advanced identity-based attacks