Padmi
Microsoft logo
Microsoft

cloud computing (Azure) · AI and machine learning (Copilot, CoreAI)

Security Researcher

Tel Aviv · OnsitePosted 6 days ago
SecuritySeniorFull Time
Apply at Microsoft

Opens the source posting on apply.careers.microsoft.com

Source description

About the role

View original

Conduct investigations of advanced threat actor activity across cloud, identity, endpoint, and on-premises environments to identify intrusion methods, attacker objectives, and operational patterns. Identify and track emerging threats, attacker techniques, campaigns, and trends to enable proactive detection, disruption, and defence before customer impact. Develop detections, mitigations, and security guidance by identifying attack paths, security weaknesses, and opportunities to strengthen defensive coverage. Build investigative tooling, automations, proof-of-concepts, and research capabilities that improve the scale and effectiveness of security investigations. Providing recommendations to improve customers' cybersecurity posture going forward and performing threat intelligence knowledge transfer to prepare customers to defend against today's threat landscape Synthesize complex technical research into clear, actionable intelligence, reports, briefings, and recommendations for technical and executive audiences. Advance understanding of nation-state, cybercriminal, and emerging threat actors through research, attribution, capability assessments, and adversary tracking. Share findings, influence strategy, and drive organizational change through knowledge transfer, best practices, and adoption of security improvements. 4+ years of experience in Threat Hunting, Incident Response (DFIR), Threat Intelligence, or Security Research. Experience investigating sophisticated cyber threats, including APT or nation-state activity. Experience working with security telemetry, logs, and SIEM platforms. Familiarity with KQL or equivalent query languages (Splunk, Humio, Kibana, etc.). Ability to analyze security data, investigate attacker behavior, and identify indicators of compromise (IOCs), indicators of activity (IOAs), and TTPs. Understanding of scripting or the ability to read and interpret code and automation workflows. Strong communication skills in English and ability to work in a global team environment. Industry certifications in cybersecurity, DFIR, incident response, or threat hunting (e.g., CISSP, GIAC). Experience identifying novel attacker techniques and translating findings into scalable detections. Experience performing malware analysis or reverse engineering. Experience analyzing large-scale security telemetry and hunting across enterprise environments.

More at Microsoft

Related open roles

View all roles