Security Researcher II /Senior Security Researcher - Microsoft Defender (Multiple Roles)
Active
Job description
Investigate real world advanced attacker TTPs to develop high-fidelity protection signals, and robust logic across complex kill-chains. Design and implement innovative capabilities that autonomously prevent, detect and disrupt sophisticated threats in near real-time. Infuse deep security expertise into the analysis of massive telemetry sets using big-data query languages, reasoning over data to identify novel malicious patterns, and drive evidence-based research decisions. Partner with engineering and product teams to share research insights, validate protection concepts, and push ideas forward into production-ready protection at a global scale. Contribute expert insights to a strategic feedback loop by analyzing real-world attack data and telemetry to refine protection coverage and accuracy. 4+ years of hands-on experience in security research or threat hunting, with a specialized focus on identity, cloud, or AI-based threat scenarios. Deep understanding of the threat landscape, including modern attacker techniques and complex kill-chains, with a focus on platform internals across OS, Cloud Workloads and Identity platforms. Experience hunting across diverse signal sources, effectively uncovering threats within on-premises, hybrid, and cloud environments. Programming proficiency (e.g., Python, C#, or similar), with a proven ability to develop and ship production-ready protection logic.Demonstrated ability to work effectively in cross-functional teams, bridging the gap between deep research and scalable engineering. Preferred Qualifications B.Sc. or M.Sc. in Computer Science or Software Engineering OR/AND related field Public track record of security research, such as technical blog posts, whitepapers, or presentations at major industry conferences. Experience in offensive security or adversary simulation.