Senior Security Researchers

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Security Research

Senior Security Researcher role focused on researching emerging attack vectors, analyzing detection/prevention gaps, and designing/developing solutions. The role involves guiding the design of AI-based solutions for security problems and has a preferred qualification in AI workflows or generative AI/LLM frameworks. The primary focus is on building security solutions, with AI being a tool to achieve that.

What you'd actually do

  1. Research emerging attack vectors and techniques.
  2. Analyze detection and prevention gaps and understand root cause.
  3. Design and develop detection, prevention and disruption solutions to thwart advanced attacks.
  4. Synthesize in-field telemetry to judge the state of threat coverage and share insights.
  5. Identify trends, foresee landscape direction and propose enhancements to meet the needs.

Skills

Required

  • Bachelor's Degree in Statistics, Mathematics, Computer Science or related field OR 3+ years experience in software development lifecycle, large-scale computing, modeling, cybersecurity, and/or anomaly detection.
  • 3+ years in reverse engineering (debuggers, disassemblers, file formats).
  • 3+ years experience with attacker kill chain analysis (MITRE ATT&CK and enterprise threat modeling).
  • 3+ years of experience in scripting and automation (Python, PowerShell, or Bash) and proficiency in at least one compiled language (e.g. C, C++, C#, Go, Rust).
  • Working experience with cloud environments, OS internals, and hybrid attacks.

Nice to have

  • Master's Degree in Statistics, Mathematics, Computer Science or related field OR 4+ years experience in software development lifecycle, large-scale computing, modeling, cyber-security, and/or anomaly detection.
  • 3+ years working with OS internals (Windows and Linux preferred).
  • 3+ years of experience in red-team/purple-team or blue-team operations across hybrid environments.
  • 3+ years authoring detection logic and security telemetry pipelines.
  • 3+ years with regex, Kusto, and/or SQL for log analysis.
  • Experience in research publication and security tooling development.
  • Working knowledge of AI workflows or generative AI/LLM frameworks.
  • Experience in vulnerability analysis and exploit development.

What the JD emphasized

  • AI based solutions
  • generative AI/LLM frameworks

Other signals

  • AI based solutions
  • generative AI/LLM frameworks