Microsoft Logo

Microsoft

Senior Security Researcher

Reposted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Sydney, New South Wales, AUS
Senior level
In-Office or Remote
Hiring Remotely in Sydney, New South Wales, AUS
Senior level
Conducts threat intelligence analysis for internal and customer-facing investigations. Supports attribution and actor modeling, analyzes adversary infrastructure and tactics, develops emerging threat clusters, and applies cloud, identity, endpoint, log, and network telemetry. Provides intelligence support to incident response teams, improves Microsoft products based on observed exploitation, briefs technical and executive stakeholders, and feeds investigation findings into threat actor tracking efforts.
The summary above was generated by AI
Overview

The Cloud & AI organization accelerates Microsoft’s mission and bold ambitions to ensure that our company and industry is securing digital technology platforms, devices, and clouds in our customers’ heterogeneous environments, as well as ensuring the security of our own internal estate. Our culture is centered on embracing a growth mindset, a theme of inspiring excellence, and encouraging teams and leaders to bring their best each day. In doing so, we create life-changing innovations that impact billions of lives around the world. Microsoft is one of the largest enterprise service companies in the world.

Do you have a passion for helping Microsoft’s clients defend themselves against targeted exploitation? Are you interested in being intimately involved in the latest, cutting-edge developments in the security industry and having a direct impact on the security of all Microsoft customers? Do you want to be on the front lines of helping our customers go toe-to-toe against advanced adversaries? Are you interested in a fast-paced job full of new opportunities? Consider applying for the Senior Security Researcher position within the Applied Intelligence team.

As an Applied Intelligence Analyst, you will apply Microsoft Threat Intelligence Center (MSTIC)’s threat intelligence to live investigations across Microsoft's products, services, and customer estates. You sit where intelligence meets incident response: enriching investigations with threat actor context, driving attribution, producing actionable intelligence, discovering and building out emerging clusters of adversary activity, and feeding what you learn back into Microsoft's threat actor tracking mission. In this role, you will collaborate with internal teams (GHOST, DART, etc.) across incident response, threat intelligence, and product groups to protect both Microsoft and Microsoft’s customers. You will strengthen existing partnerships and build new ones with key organizations to deliver benefits to Microsoft and its customers.


Responsibilities
  • Investigation support. Providing threat intelligence support to proactive security research and reactive incident response engagements across both internal and customer-facing investigations.
  • Attribution and actor modeling. Ingesting, modeling, attributing, and documenting intelligence collected during engagements. Owning the attribution lane while investigation partners lead forensics and customer response.
  • Supporting Partner Teams: Providing attribution analysis and intelligence support to Microsoft Security partner teams investigating and responding to threats.
  • Product Improvements: Ensuring observations of threat actor exploitation of Microsoft products and services translate into product improvements.
  • Emerging threats. Discovering untracked clusters of activity with novel capabilities, developing them into tracked threat groups through in-depth research across the Diamond Model and multiple Microsoft telemetry sources, and helping Microsoft stay on top of the latest and newest threats.
  • Briefing and delivery. Delivering threat intelligence briefings to external customers and internal stakeholders. Supporting notifications to customers regarding imminent or ongoing attacker activity.
  • Feedback loop. Ensuring intelligence collected during reactive investigations— novel capabilities, infrastructure, targeting, or tradecraft — is promptly collated and surfaced back to Microsoft's actor tracking teams in MSTIC.

Qualifications
Required/minimum qualifications
Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
 
  • Outstanding technical knowledge of adversary capabilities, infrastructure, and techniques, and the ability to develop new methods to discover and track them.
  • Experience tracking advanced financially motivated or state-sponsored adversaries using the Diamond Model; ability to characterize TTPs, infrastructure, and operational campaigns.
  • Demonstrated experience producing actionable intelligence that changed the outcome of an investigation or hardened a defended network.
  • Familiarity with host, log, and network forensics, common protocols, and a range of adversary command-and-control methods.
  • Demonstrated experience with log analysis and query languages (KQL/Kusto, SQL, or equivalent) across SIEM, identity, endpoint, or cloud telemetry.
  • Experience with large-scale cloud, identity, and endpoint telemetry.
  • Experience supporting incident response and familiarity with common IR procedures and tooling.
  • Ability to communicate findings clearly, with appropriate confidence language, to technical and executive audiences.
 
 
Preferred qualifications
  • Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience.
  • Background in cloud and identity-based intrusions — token theft, OAuth abuse, SaaS-native tradecraft
  • Detection engineering or hunting query development at scale
  • Use of automation, data science, or AI tooling to accelerate triage, clustering, and analysis
  • Experience delivering customer or executive briefings under time pressure during active incidents
  • Working knowledge of malware used in targeted campaigns, including triage of malicious capabilities.
  • Familiarity with Microsoft security data sources - MDC, Defender XDR, Sentinel, Azure Resource Graph.

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.



Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Similar Jobs

2 Hours Ago
In-Office or Remote
Senior level
Senior level
Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Lead the AI Quality engineering team while remaining hands-on building evaluation infrastructure, CI/CD pipelines, scorers, datasets, observability tooling, and diagnostic systems for production AI agents. Design experiments across prompts and models, improve agent reliability, latency, and cost, develop annotation and simulation workflows, and partner with AI Core engineering to validate product changes.
Top Skills: Ai AgentsAnnotation WorkflowsBraintrustCachingCi/CdDatasetsEvaluation InfrastructureLangsmithLlmsModel RoutingObservability ToolingPythonRuby On Rails
2 Hours Ago
In-Office or Remote
Senior level
Senior level
Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
The Senior Quality Engineer partners with product, design, and engineering teams to build quality throughout the development lifecycle. Responsibilities include exploratory and risk-based testing, web and API automation, technical investigation, CI/CD test execution, identifying product risks, improving testability and reliability, and driving organization-wide quality practices. The role also supports reusable quality platforms, automation frameworks, developer tooling, and scalable quality improvements.
Top Skills: AndroidApi TestingCi/CdIntegration TestingiOSPlaywrightReact NativeTypescript
2 Hours Ago
In-Office or Remote
Senior level
Senior level
Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Lead the AI Quality engineering team while remaining hands-on building evaluation infrastructure, observability tooling, diagnostic systems, datasets, annotation workflows, and CI/CD pipelines for production AI agents. Run experiments across prompts, models, routing, caching, and agent harnesses to improve quality, latency, and cost. Partner with AI Core engineering and manage technical direction and team priorities.
Top Skills: Ai AgentsBraintrustCi/CdLangsmithLlmsPythonRuby On Rails

What you need to know about the Sydney Tech Scene

From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account