Source description
About the role
Set the technical direction for a major area of our identity protection research charter, owning the multi-quarter strategy from threat landscape framing to shipped detection and measurable customer protection impact. Drive multiple concurrent end-to-end research initiatives, breaking ambiguous problems into tractable workstreams and unblocking the team on the hardest technical questions. Lead deep investigation and research of data across identity and adjacent sources to surface novel threats, attacker tradecraft, and detection opportunities others miss. Stay ahead of the evolving attacker landscape and design robust, sophisticated detection logics across the entire kill-chain — raising the bar on quality, coverage, and resilience to attacker evasion. Influence across organizational boundaries — partner with product management, engineering, data science, and peer research teams to shape product strategy, define new identity protection capabilities, and align roadmaps on a data-driven foundation. Mentor and grow other researchers, elevating the technical bar of the team through code/design review, research coaching, and apprenticeship on complex investigations. Shape how the team and discipline leverage Generative AI — define patterns, evaluate tools, and build durable AI-assisted workflows that scale research throughput across data triage, hypothesis generation, code and KQL authoring, and detection synthesis. You have at least 10+ years of cyber security experience, including 4+ years working hands-on with identity-based attacks (research, hunting, or detection engineering) on top of the modern attacker kill-chain and MITRE ATT&CK. You have passion for defensive work - hunting, investigation, detection authoring, and protection enforcement design — with a track record of owning research end-to-end, from threat hypothesis to shipped detection and customer impact. You have Windows internals knowledge, along with working knowledge of the main identity protocols (e.g., Kerberos, NTLM, LDAP, OAuth 2.0, SAML). You demonstrated fluency leveraging Generative AI tools (e.g., GitHub Copilot, Security Copilot, ChatGPT/Claude) to multiply daily research output — including prompt design, model-output validation, and integrating AI assistance into investigation, coding, and detection authoring. B.Sc./M.Sc. in Computer Science or related technical discipline. Good knowledge of at least one programming language such as C# (preferred), Python, or C++, and at least one query language such as KQL, SQL, or Cypher. Experience with Windows and/or Cloud forensics — key artifacts around credential theft and lateral movement across on-prem and hybrid identity environments. Experience authoring security research (papers, blogs, conference talks such as BlueHat / Black Hat / DEF CON, or CVEs). Experience building or applying AI/LLM-assisted workflows for security research, detection engineering, or threat intelligence at scale. Established external thought leadership in the security research community — e.g., authored research papers, conference talks (Black Hat, DEF CON, USENIX, RSA, BlueHat, or equivalent), high-impact blogs, CVEs, or open-source contributions. Excellent cross-group, leadership, and interpersonal skills, with the ability to influence without authority.
More at Microsoft
Related open roles
Program Manager, Global Security Access Management (GSAM)
Seattle · Onsite
Principal Technical Advisor for Cybersecurity Incident Response
Seattle · Dallas–Fort Worth · Onsite
Senior Security Researcher
Seattle · Washington DC · Onsite
Security Engineer
London · Dublin · Onsite
Security Cloud Solution Architect- CTJ - Poly
Washington DC · Onsite
Senior Cloud Solution Architect - Security / Global Solutions
Tokyo · Onsite